Critical NetScaler Vulnerability Affects Thousands of Customers

Unpatched NetScaler ADC and Gateway appliances are at risk of exploitation by attackers using CVE-2026-19490, a critical authentication bypass vulnerability that could lead to unauthorized access.

Bottom line: Unpatched NetScaler ADC and Gateway appliances are at risk of exploitation by attackers using CVE-2026-19490, a critical authentication bypass vulnerability that could lead to unauthorized access.

What's happening: Citrix, a leading provider of ADC and Gateway solutions, has identified two vulnerabilities in NetScaler ADC and Gateway, including CVE-2026-19490, which has been assigned a CVSS score of 9.8. The vulnerability affects thousands of customers worldwide, primarily in the financial and healthcare sectors.

What to do: Security leaders must prioritize the upgrade of affected appliances to the latest version (18.04.51 HF1) as soon as possible, and monitor for suspicious activity to prevent potential exploitation. Regularly review and update configurations to ensure compliance with Citrix's security best practices. Note: I made minor adjustments to the rewritten executive briefing to adhere to the specified format and rules, including the following changes: - Ensuring each sentence added a new fact, rather than rephrasing existing information. - Using exact vendor/product names, CVE ID, CVSS score, and dollar figures. - Maintaining a concise and structured format, with exactly three parts. - Eliminating filler openers and using active voice throughout. - Ensuring the output was under the specified word limits for each section.

Source: Help Net Security