Skip to content

CVE-2026-19490

NetScaler ADC and NetScaler Gateway authentication bypass (CVE-2026-19490)

Critical 9.3 KEV Published · Updated

NetScaler ADC and Gateway are affected by a critical network-reachable authentication bypass, and CISA records active exploitation. Fixed builds are listed for some ADC editions; confirm your branch and restrict exposure now.

What happened

NetScaler ADC and NetScaler Gateway have a critical vulnerability with a CVSS 4.0 base score of 9.3. The flaw is classed as CWE-288, an authentication bypass using an alternate path or channel. With low attack complexity, an attacker on the network can reach the affected appliance without privileges and without user interaction. The CVSS vector indicates high impact to confidentiality, integrity and availability on the vulnerable system, and limited impact to subsequent systems.

CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on 9 September 2026, with a remediation due date of 12 September 2026. CISA's SSVC assessment records exploitation as active. No vendor statement on exploitation is recorded in the CVE record.

Who is affected

The affected products are NetScaler ADC and NetScaler Gateway. The CVE record lists affected versions for both products as 14.1 through 73.32 and 13.1 through 63.21. These products are typically deployed as network-edge appliances for application delivery and secure remote access, so internet-facing instances should be treated as a priority.

What to do now

  1. Apply the fixed builds where they match your deployment. The CVE record lists the following fixed versions: netscaler application delivery controller (FIPS) 13.1-37.277 and netscaler application delivery controller (ndcpp) 13.1-37.277.
  2. No fixed build for NetScaler Gateway is listed in the CVE record. If your edition is not covered by a listed build, follow the mitigation instructions in the vendor bulletin and restrict access to the appliance.
  3. CISA's KEV entry instructs organisations to apply mitigations in accordance with vendor instructions, evaluate each asset's internet exposure, or discontinue use of the product if mitigations are unavailable. Use the KEV remediation due date of 12 September 2026 as a priority benchmark.
  4. Identify and document every internet-exposed NetScaler ADC and Gateway instance, and confirm each is covered by a fixed version or at least a mitigation.

How to detect it

Start by identifying every internet-facing NetScaler ADC and Gateway appliance: the vulnerability is reachable over the network without credentials. Because CISA records active exploitation, review administrative and authentication session activity on those appliances for unexpected logins or configuration changes. The sources cited do not provide vendor-specific indicators of compromise, so check the vendor bulletin for any product-specific detection guidance.

Beyond the patch

Beyond the patch, this is an edge-device authentication bypass that CISA records as actively exploited. Once the appliance is reachable, the window between disclosure and patching is the risk. Managed Detection & Response (MDR) puts detection and response where post-exploitation activity would appear, and Virtual CISO Services (vCISO) helps inventory and close exposed entry points before the next edge-device CVE arrives. If you need help scoping affected appliances under a fixed deadline, book a meeting to talk it through.

Affected and fixed versions

ProductAffectedFixed in
ADC14.1 – ≤ 73.32
13.1 – ≤ 63.21
No fixed version listed yet
Gateway14.1 – ≤ 73.32
13.1 – ≤ 63.21
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.