NetScaler ships a critical authentication bypass affecting Gateway and AAA virtual servers
CVE-2026-19490 (CVSS 9.3) bypasses authentication on NetScaler ADC and Gateway appliances running a Gateway or AAA virtual server, with a SAML action configured on current builds. Fixed in 14.1-73.32 and 13.1-63.21.
Cloud Software Group disclosed two NetScaler flaws on August 19, 2026. CVE-2026-19490 (CVSS 9.3) is an authentication bypass reaching appliances configured as a Gateway virtual server (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server; on current builds the vendor scopes it to configurations with a SAML action bound, while earlier builds in each branch are affected without that prerequisite. CVE-2026-19489 (CVSS 8.8) is a memory overflow in the same bulletin. Affected: 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, plus FIPS and NDcPP variants. No exploitation observed at disclosure. Versions 12.1 and 13.0 are end of life and get no fix.
Why it matters
A NetScaler running Gateway or AAA is the authentication boundary for remote access, and often the policy decision point for what sits behind it. Bypassing authentication there makes the MFA policy and the device posture check decorative, because the request arrives past the component that evaluates them. Treat the "no known exploitation" line with less comfort than it reads: CitrixBleed went from disclosure to mass session hijacking and ransomware in weeks, and CitrixBleed 2 repeated it. Internet-facing identity appliances get exploited fast because the prize is a live session, and a session survives the password reset you do afterwards. Patch, then terminate every AAA and ICA session and rotate the LDAP and RADIUS bind accounts and SAML signing keys the appliance holds, because patching a bypass does not evict whoever already used it.
Source: The Hacker News
Related on Start with Identity
- BlogA 9.8-CVSS vCenter authentication bypass has no workaround, only an emergency patch
Broadcom shipped emergency fixes for three critical VMware flaws, including CVE-2026-59309 (CVSS 9.8), which lets any attacker with network access to vCenter by
- BlogEvery on-premises TeamCity server is vulnerable to an auth bypass in the agent polling protocol
CVE-2026-63077 lets an unauthenticated attacker abuse TeamCity's agent polling protocol to bypass authentication and run arbitrary OS commands with the server p
- BlogForged OIDC tokens in SimpleHelp RMM handed out technician access to 1,000 exposed servers, no MFA required
CVE-2026-48558 lets an unauthenticated attacker forge OpenID Connect tokens against SimpleHelp remote-monitoring software configured for group login, gaining pr
- CVEIvanti Connect Secure authentication bypass
Connect Secure and Policy Secure skipped authentication on a path that later chained with CVE-2024-21887 for unauthenticated RCE. CISA KEV. January 2024 disclos
- CVEIvanti Sentry authentication bypass
Ivanti Sentry (MobileIron Sentry) skipped authentication on an administrative API. CISA KEV. August 2023. The gateway in front of EPMM had its own unlocked door
- CVEJetBrains TeamCity 2023 authentication bypass to RCE
Unauthenticated request becomes administrator, then code execution, on TeamCity On-Premises before 2023.05.4. CVSS 9.8. CISA KEV. Used by Russian state actors.