What happened
Citrix has released patches for CVE-2026-19490, a critical authentication bypass in NetScaler ADC and NetScaler Gateway appliances, and security firms spent August 20 urging administrators to treat it as an emergency. The flaw, scored 9.3 on the CVSS scale, allows a remote attacker to bypass login checks through an alternate path — no credentials or user interaction required — on appliances configured as a gateway, including SSL VPN, ICA Proxy, and RDP Proxy setups, or as an AAA virtual server. Fixes are available in NetScaler versions 14.1-73.32 and 13.1-63.21, along with updated FIPS builds. Citrix also patched CVE-2026-19489, a high-severity memory overflow that can cause denial of service when SIP ALG is enabled. Rapid7 said it had not observed exploitation as of August 19 but urged organizations to patch on an emergency basis, because NetScaler devices sit at the network edge and flaws in them have historically been exploited within days of disclosure.
Why it matters for your business
NetScaler gateways are exactly the kind of device a smaller company inherits from an IT provider and forgets about. They face the internet, they guard remote access to everything behind them, and earlier NetScaler flaws fueled ransomware campaigns against organizations of every size — not just enterprises. An authentication bypass on a remote-access gateway is effectively an unlocked front door, and attackers routinely scan the whole internet for vulnerable appliances the moment a patch drops.
What to do about it
- If you run NetScaler ADC or Gateway, apply the fixed build now rather than waiting for a normal maintenance window.
- If an MSP manages your remote access, ask them today which version you are running and when it will be patched.
- Once patched, review gateway logs for logins that don't match known users or locations.
