Start with Identity
← Blog
News

NetScaler ships a critical authentication bypass affecting Gateway and AAA virtual servers

CVE-2026-19490 (CVSS 9.3) bypasses authentication on NetScaler ADC and Gateway appliances running a Gateway or AAA virtual server, with a SAML action configured on current builds. Fixed in 14.1-73.32 and 13.1-63.21.

By SWI Community TeamAug 19, 2026Updated Aug 29, 2026

Cloud Software Group disclosed two NetScaler flaws on August 19, 2026. CVE-2026-19490 (CVSS 9.3) is an authentication bypass reaching appliances configured as a Gateway virtual server (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server; on current builds the vendor scopes it to configurations with a SAML action bound, while earlier builds in each branch are affected without that prerequisite. CVE-2026-19489 (CVSS 8.8) is a memory overflow in the same bulletin. Affected: 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, plus FIPS and NDcPP variants. No exploitation observed at disclosure. Versions 12.1 and 13.0 are end of life and get no fix.

Why it matters

A NetScaler running Gateway or AAA is the authentication boundary for remote access, and often the policy decision point for what sits behind it. Bypassing authentication there makes the MFA policy and the device posture check decorative, because the request arrives past the component that evaluates them. Treat the "no known exploitation" line with less comfort than it reads: CitrixBleed went from disclosure to mass session hijacking and ransomware in weeks, and CitrixBleed 2 repeated it. Internet-facing identity appliances get exploited fast because the prize is a live session, and a session survives the password reset you do afterwards. Patch, then terminate every AAA and ICA session and rotate the LDAP and RADIUS bind accounts and SAML signing keys the appliance holds, because patching a bypass does not evict whoever already used it.

Source: The Hacker News

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.