
🚨 CVE-2026-19490 — Citrix NetScaler ADC & Gateway, authentication bypass (CVSS 9.3) What broke: On appliances used as a Gateway (SSL VPN, ICA Proxy, Clientless VPN, or RDP Proxy) or as an AAA virtual server, a request could take an alternate path and skip the login check (CWE-288). Unauthenticated, no user interaction. Who should care: Customer-managed NetScaler ADC/Gateway — 14.1 before 14.1-73.32, 13.1 before 13.1-63.21, plus 14.1-FIPS before 14.1-73.32 FIPS and 13.1-FIPS/NDcPP before 13.1-37.277. Secure Private Access Hybrid instances on those builds are in scope. Citrix-managed cloud services and Adaptive Authentication were patched centrally. Preconditions aren’t one-size-fits-all: on 14.1-43.56+ (and matching later FIPS), you need a SAML action andGateway/AAA. On older 14.1 / older 13.1 / 13.1 FIPS, Gateway or AAA alone is enough. On 13.1-61.28+, Citrix’s trigger is a configured SAML action. Risk: This is the remote-access front door, not a dusty management port. There is no workaround in Citrix bulletin CTX696939. NetScaler Console Global Deny List signatures can reduce exposure on some mid-train builds; they are not the fix. Status: Actively exploited. Fix shipped 19 Aug with no known exploitation that day. Public PoC ~2 Sept, probes from 3 Sept, CISA KEV on 9 Sept, federal due date 12 Sept. Same “patch now, mass-scan next” arc as CitrixBleed, CitrixBleed 2, and CVE-2025-7775. Fix: 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, or 13.1-37.277. If you can’t patch today: restricting NSIP/mgmt to a dedicated VLAN does not close this hole. Inventory Gateway/AAA + add authentication samlAction and treat internet-facing boxes as emergency. Source: CTX696939 / CISA KEV #Citrix #NetScaler
Post summary
The post reports active exploitation of a high-severity Citrix NetScaler authentication bypass and cites CISA KEV. It provides affected versions, technical conditions, and fixed releases, while also noting a public PoC.



