logo

CVE-2026-19490: Critical Citrix NetScaler Authentication Bypass Exposes Enterprise Gateways

ID: 6b9a05a9-2ceb-573b-92cc-db328f327f47

STIX ID: report--6b9a05a9-2ceb-573b-92cc-db328f327f47

Feed Name: SOC Prime Blog

Threat Score
80/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: SOC Prime Team

...
...

## Executive summary Cloud Software Group has released patches for CVE-2026-19490, a critical (CVSS 9.3) authentication bypass in NetScaler ADC/Gateway that can allow unauthenticated remote attackers to access protected services when specific Gateway/AAA or SAML configurations are present; affected 13.1 and 14.1 branches must be upgraded to the vendor's fixed builds and administrators should prioritize internet-facing appliances, review authentication/SAML logs for anomalous sessions, and preserve historical logs for forensic review.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.