Citrix Patches Critical Login-Bypass Flaw in NetScaler, Attacks Expected Soon

A security hole rated 9.3 out of 10 lets criminals walk straight past the login screen on widely used corporate network gear. Patches are out now, and researchers say exploitation is a matter of when, not if.

ThreatVectr Newsdesk· 3 min read
Close-up overhead view of dense rack-mounted network hardware in a dimly lit server room, indicator lights glowing amber and red across multiple units, cables b
Share

Key points

  • Citrix released patches on Wednesday for two flaws in NetScaler ADC and NetScaler Gateway, its widely deployed corporate networking products.
  • The critical flaw, CVE-2026-19490, scores 9.3 out of 10 on the standard severity scale and lets an outside attacker bypass login entirely, no password required.
  • Fixed software versions include NetScaler 14.1-73.32 and 13.1-63.21, among others; any installation running an older build is at risk.
  • Cybersecurity firm Rapid7 has seen no attacks in the wild yet, but warns that NetScaler devices are attractive, publicly reachable targets that criminals move against quickly.
  • A second, high-severity flaw, CVE-2026-19489, can crash affected systems under certain configurations.

What happened?

Citrix has published emergency patches for two security flaws in NetScaler ADC and NetScaler Gateway, products that sit at the front door of corporate networks and control who gets in. The more serious of the two lets an attacker log straight into a system without knowing any credentials.

NetScaler ADC, short for Application Delivery Controller, is software that manages and balances the flow of internet traffic into a company's internal systems. NetScaler Gateway is the companion product that lets employees connect securely from home or on the road, functioning as a kind of guarded entrance. Both products are typically placed where the internet meets a company's private network, meaning they are reachable by anyone on the web.

How bad is the critical flaw?

Bad enough that organisations should treat patching as an emergency, not a scheduled task. CVE-2026-19490 is an authentication bypass, meaning it lets a criminal skip the login process entirely by approaching the device through an alternative, unprotected path the software wasn't supposed to expose.

No special knowledge is needed. No staff member has to click anything. A criminal sitting anywhere on the internet can attempt the attack alone.

Rapid7, which analysed the flaw, notes that NetScaler appliances sit in what network teams call the DMZ, a segment of the network deliberately exposed to the outside world. That exposure is the whole point of the product, but it also means every vulnerable installation is one internet request away from an attacker.

Detail Value
Critical flaw ID CVE-2026-19490
Severity score 9.3 / 10
Second flaw ID CVE-2026-19489
Second flaw severity High
Patched version (standard) 14.1-73.32 / 13.1-63.21
Patched version (FIPS) 14.1-73.32 FIPS / 13.1-37.277

The second vulnerability, CVE-2026-19489, is a memory overflow issue, where the software is fed more data than it can handle, causing it to crash or behave unpredictably. It only triggers when a specific voice-and-video routing feature, called SIP ALG, is switched on inside a particular network configuration. Disruptive, but less immediately dangerous than the login bypass.

Should IT teams be worried?

Yes, and urgently. Citrix products have a documented history of being attacked within days of a public patch, because publishing a patch effectively tells criminals exactly where to look. Rapid7 said it expects exploitation of CVE-2026-19490 to begin shortly, based on that pattern and the sheer number of NetScaler devices reachable from the internet.

Organisations running Secure Private Access hybrid deployments, a setup mixing Citrix's cloud service with on-premises NetScaler hardware, are also affected and need the same updates, according to Citrix's advisory.

If you work in IT at a company that uses NetScaler, check your version numbers now and apply the patches. SecurityWeek first reported the disclosure.

© 2026 Threat Vectr