# Critical Citrix NetScaler authentication bypass prompts emergency patching

_Published Wednesday, August 19, 2026 at 11:18 PM EDT · Security, Infrastructure · Breaking · Tier 1 — Major_

![Critical Citrix NetScaler authentication bypass prompts emergency patching — Primary](https://www.rapid7.com/cdn/images/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp)

A security advisory published August 19 details CVE-2026-19490, a critical authentication-bypass flaw in Citrix NetScaler ADC and NetScaler Gateway. Rapid7 says the remotely exploitable issue has a CVSS v4.0 score of 9.3 and requires neither authentication, user interaction nor elevated privileges. Affected releases include NetScaler ADC and Gateway 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, along with specified FIPS and NDcPP versions. Rapid7 says it has not observed exploitation in the wild but advises emergency patching of affected systems.

## Sources

- [rapid7.com](https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway/)
- [heise.de](https://www.heise.de/en/news/Citrix-patches-critical-login-bypass-in-Netscaler-ADC-and-Gateway-11420409.html)

---
Canonical: https://techandbusiness.org/newswire/JFRLEcImHUWyb2B2_X3uoA
Published: 2026-08-20T03:18:07.050Z
Story chronology: 2026-08-19T16:48:05.440Z
Retrieved: 2026-10-04T09:26:24.164Z
Publisher: Tech & Business (techandbusiness.org)
