Cloud Software Group has released urgent security patches for CVE-2026-19490, a critical authentication bypass vulnerability affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway. The vulnerability is rated 9.3 on the CVSS v4.0 scale and allows a remote, unauthenticated attacker to completely bypass authentication on configured gateway or AAA virtual servers. Successful exploitation could lead to unauthorized access to internal network resources. Although exploitation has not been observed in the wild, the vulnerability's nature makes it a prime target for attackers. A second high-severity denial-of-service flaw, CVE-2026-19489 (CVSS 8.8), was also patched. All customers are advised to update their appliances immediately.
CVE-2026-19490 is classified as an authentication bypass using an alternate path or channel (CWE-288). It enables an attacker to circumvent security controls on NetScaler appliances under specific configurations.
CVE-2026-19489 is a memory overflow vulnerability that can be triggered by an attacker to cause a denial-of-service condition, crashing the appliance.
The vulnerabilities affect multiple versions of NetScaler ADC and NetScaler Gateway. Cloud Software Group has released the following patched versions:
Customers running versions prior to these are vulnerable and should prioritize updating.
As of the advisory's release, there were no public reports of CVE-2026-19490 or CVE-2026-19489 being exploited in the wild. However, due to the critical nature of the authentication bypass and the history of threat actors rapidly targeting NetScaler vulnerabilities, security experts widely expect that exploits will be developed and used against internet-facing systems in the near future. Organizations should operate under the assumption that exploitation is imminent.
A successful exploit of CVE-2026-19490 presents a significant threat to organizations. By bypassing authentication on a NetScaler Gateway, an attacker could:
T1133 - External Remote ServicesThe impact is amplified because these devices are intentionally internet-facing and designed to be the primary gateway for remote access, making them a single point of failure if compromised.
Since an exploit is not yet public, specific IOCs are unavailable. However, security teams can hunt for anomalous activity related to their NetScaler appliances:
NetScaler syslog / ns.logInternal access from NetScaler IPsVPN/AAA logsshow aaa sessionD3-NTA: Network Traffic Analysis to detect post-exploit behavior. Also, D3-RAPA: Resource Access Pattern Analysis can help identify when an attacker, having bypassed authentication, starts accessing resources in a way that differs from legitimate users.D3-NI: Network Isolation ensures that even if the gateway is compromised, the blast radius is contained.Applying the vendor-supplied patches is the most direct and effective way to mitigate this vulnerability.
Segmenting the network to restrict what a compromised gateway can access helps contain the blast radius of a successful exploit.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.