CVE-2026-19490
NetScaler ADC and NetScaler Gateway authentication bypass (CVE-2026-19490)
NetScaler ADC and Gateway are affected by a critical network-reachable authentication bypass, and CISA records active exploitation. Fixed builds are listed for some ADC editions; confirm your branch and restrict exposure now.
What happened
NetScaler ADC and NetScaler Gateway have a critical vulnerability with a CVSS 4.0 base score of 9.3. The flaw is classed as CWE-288, an authentication bypass using an alternate path or channel. With low attack complexity, an attacker on the network can reach the affected appliance without privileges and without user interaction. The CVSS vector indicates high impact to confidentiality, integrity and availability on the vulnerable system, and limited impact to subsequent systems.
CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on 9 September 2026, with a remediation due date of 12 September 2026. CISA's SSVC assessment records exploitation as active. No vendor statement on exploitation is recorded in the CVE record.
Who is affected
The affected products are NetScaler ADC and NetScaler Gateway. The CVE record lists affected versions for both products as 14.1 through 73.32 and 13.1 through 63.21. These products are typically deployed as network-edge appliances for application delivery and secure remote access, so internet-facing instances should be treated as a priority.
What to do now
- Apply the fixed builds where they match your deployment. The CVE record lists the following fixed versions: netscaler application delivery controller (FIPS) 13.1-37.277 and netscaler application delivery controller (ndcpp) 13.1-37.277.
- No fixed build for NetScaler Gateway is listed in the CVE record. If your edition is not covered by a listed build, follow the mitigation instructions in the vendor bulletin and restrict access to the appliance.
- CISA's KEV entry instructs organisations to apply mitigations in accordance with vendor instructions, evaluate each asset's internet exposure, or discontinue use of the product if mitigations are unavailable. Use the KEV remediation due date of 12 September 2026 as a priority benchmark.
- Identify and document every internet-exposed NetScaler ADC and Gateway instance, and confirm each is covered by a fixed version or at least a mitigation.
How to detect it
Start by identifying every internet-facing NetScaler ADC and Gateway appliance: the vulnerability is reachable over the network without credentials. Because CISA records active exploitation, review administrative and authentication session activity on those appliances for unexpected logins or configuration changes. The sources cited do not provide vendor-specific indicators of compromise, so check the vendor bulletin for any product-specific detection guidance.
Beyond the patch
Beyond the patch, this is an edge-device authentication bypass that CISA records as actively exploited. Once the appliance is reachable, the window between disclosure and patching is the risk. Managed Detection & Response (MDR) puts detection and response where post-exploitation activity would appear, and Virtual CISO Services (vCISO) helps inventory and close exposed entry points before the next edge-device CVE arrives. If you need help scoping affected appliances under a fixed deadline, book a meeting to talk it through.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| ADC | 14.1 – ≤ 73.32 13.1 – ≤ 63.21 | No fixed version listed yet |
| Gateway | 14.1 – ≤ 73.32 13.1 – ≤ 63.21 | No fixed version listed yet |