A critical vulnerability in Citrix NetScaler ADC and NetScaler Gateway is actively attacked. This concerns CVE-2026-19490, which allows for the avoidance of normal authentication under specific configurations. Citrix published security updates on August 19th. The NCSC warned on August 20 about the vulnerability. Early September, security investigators reported observed exploitation attempts.

What is CVE-2026-19490?

CVE-2026-19490, is a vulnerability in NetScaler ADC and NetScaler Gateway. Citrix assesses the security bulletin as Critical. The vulnerability has a CVSS v4 score of 9.3.

Under certain conditions, an attacker can bypass the normal authentication via an alternative route and gain unauthorized access without valid login data. The vulnerability applies when an affected version is configured as Gateway or AAA virtual server. Depending on the build used, the presence of a SAML action also plays a role.

Not every NetScaler installation is automatically vulnerable. The version and configuration used determine the exposure. Therefore check the current Citrix bulletin and have the configuration evaluated by an expert administrator.

  • Gateway or SSL VPN
  • ICA Proxy
  • CVPN
  • RDP Proxy
  • AAA virtual server
  • certain versions and configurations with a SAML action
You can only patch what you know you have. Therefore, keep up to date with which systems are connected to the Internet, which version and configuration they use, and who is responsible for patching and investigation after a security alert.

Which versions should be updated?

Citrix lists the supported versions below as affected. Always use the current security bulletin as the leading source before making changes. The bulletin also contains commands that allow administrators to determine whether an application meets the configuration conditions.

Citrix urges affected organisations to upgrade to a restored version as soon as possible. The bulletin does not mention workaround that replaces patching.

  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.32
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-63.21
  • NetScaler ADC 14.1 FIPS before 14.1-73.32 FIPS
  • NetScaler ADC 13.1 FIPS and NDcPP before 13.1-37.277

Active abuse attempts change the priority

A vulnerability for which only technical information is available already requires assessment. Once security investigators detect exploits, risk weighting changes. A regular patch round next month may not be sufficiently fast.

Previdian reported requests for NetScaler sensors that were in line with the publicly known operating method at the beginning of September. These observations indicate exploitation attempts. They do not confirm successful compromise of real organisations. The NCSC opinion of 20 August describes the vulnerability and solution, but does not mention this later perception of abuse attempts.

For an internet-facing access system, the priority should be high when the version and configuration appear vulnerable. A workable patch process distinguishes between regular updates, important security updates, critical vulnerabilities and vulnerabilities that are actively attacked.

Only patching is not always enough when you are active

The patch prevents new abuse of CVE-2026-19490. The installation does not tell you whether an attacker has already tried to access or has succeeded before the patch moment. If a vulnerable NetScaler was accessible from the internet, then assess whether research into possible compromise is necessary.

Look for abnormal authentications, unknown accounts, configuration changes, suspicious processes, unexpected network connections and deviations in NetScaler, VPN, AAA and SAML logs. Compare observations with current information from Citrix and other reliable security sources.

When compromise is suspected, forensic care is important. Save relevant logs, system information and other tracks before cleaning or reinstalling without a plan. Among other things, Citrix recommends to secure evidence, isolate the application, replace potentially affected credentials and certificates and investigate connected systems.

First steps after a cyber incident

The broader lesson: Know what's on your Internet

The NetScaler case is about more than Citrix. Firewalls, VPN gateways, routers, load balancers, mail servers, web servers, portals and management interfaces are often on the edge of the network. That makes them interesting for attackers.

In practice, organisations do not always have a full and up-to-date picture of what is accessible from the Internet. An old VPN remains temporarily online, a test environment is forgotten after a project or a supplier opens a management interface without being centrally registered. That's an asset management problem.

The first question in a new vulnerability should not take two days: do we use this product? The answer must be readily available so that version, configuration, internet accessibility and urgency can be assessed immediately.

  • Firewalls, routers and VPN gateways
  • load balancers and remote access features
  • mail servers, web servers and portals
  • NAS, camera and access control systems
  • IP and industrial equipment
  • cloud assets, subdomains and supplier management interfaces

What is asset management for information security?

Asset management means that you can be shown to know what relevant business resources you use, what their function and critical importance is and who is responsible for it. This does not require a complex CMDB with thousands of fields. Start with the data needed to assess risks and vulnerabilities quickly.

For equipment that is directly accessible from the internet, this information should be available with high reliability. Register the system when it is in use, appoint owner and administrator, follow lifecycle and support status and then unlock the asset when it is no longer needed.

  • name, location and function of the system or device
  • current software or firmware version
  • owner, administrator and patch manager
  • internet accessibility and available management interfaces
  • processed data and supported business processes
  • critical importance, support status and end of support
  • agreements on patching, logging and monitoring

An asset registry alone is not enough

A register that is built once and is not kept after that, is rapidly ageing. Asset management is therefore a process: register, assign, classify, modify, periodically check and eventually delete ownership.

A spreadsheet or CMDB describes what the organisation thinks it says. An external scan shows what is actually visible from the internet. Compare those images periodically. For example, check public IP addresses, DNS records, open ports, internet-facing services, TLS certificates, VPN interfaces, management portals, cloudassets and forgotten systems.

This is also called external attack surface management. For many organisations heavy continuous tooling is not the first requirement. A periodic independent check may already reveal whether what is found outside corresponds to what is recorded and intended internally.

Asset management and patch management are part of each other

Patch management only works when you know if you are using the affected product, which version is present, where it runs, how it is configured, whether it is accessible from the Internet and who is responsible for the update.

Good patch management and vulnerability management Therefore, link security warnings to a current asset registry, clear priorities, ownership, execution and verification. This enables the organisation to determine directly: We have this, are we vulnerable and who should act now?

Five questions you can ask today

These five questions quickly provide insight into the connection between your digital attack surface, asset management and patch process.

1. Do we know which systems are directly accessible from the internet?

Look beyond websites. Also include VPN, remote access, firewalls, routers, cloud services and management interfaces.

2. Do we know which versions and configurations run on them?

A product name without a version and relevant configuration data is not sufficient to quickly assess a vulnerability.

3. Is it clear who is responsible for updates?

Check that, when outsourced, responsibilities, deadlines, verification and reporting are demonstrably recorded in agreements, SLA or DAP.

4. Can we see in a few hours if a new CVE applies to us?

When extensive search for product, version, owner or internet accessibility is first necessary, asset management is probably not mature enough.

5. After observed abuse, are we also checking for compromise?

A patch prevents new abuse. He doesn't prove that the system was clean before installation.

- Exempted management? Ask for proof

Many NetScaler environments are managed by an external IT service provider. The announcement that the supplier is regulating updates does not provide sufficient certainty in the event of a critical vulnerability. Ask for concrete answers and appropriate evidence.

Sub-contracting of management does not change the organisation's responsibility for its own risks and data. Make sure that it is clear who is judging, who is acting, who is controlling and who is reporting on the remaining risk.

  • Do we use NetScaler ADC or NetScaler Gateway?
  • Which version and relevant configuration are currently running?
  • Does our facility fall within the terms of CVE-2026-19490?
  • When was the security update installed and how was this verified?
  • Was the system vulnerable before patching and accessible from the Internet?
  • Has any evidence of compromise been checked and what has been recorded?

What do you do at Citrix NetScaler now?

Are you using NetScaler ADC or NetScaler Gateway? Then proceed at least the following actions. Have version, configuration and compromise research conducted by someone with sufficient technical knowledge of NetScaler and incident response.

  • 1. Invent all NetScaler instances present.
  • 2. Check version and configuration against the current Citrix security bulletin.
  • 3. Update directly to a recovered version when vulnerability applies.
  • 4. Review possible compromise when the system has been vulnerable and internet-facing.
  • 5. Keep relevant logs and tracks when you find anomalies.
  • 6. Check management agreements and proof when a supplier maintains the system.
  • 7. Record the asset correctly, including owner, version, exposure and patch responsibility.

From one Citrix leak to structural resilience

CVE-2026-19490, will eventually disappear from the news. The following critical vulnerability comes naturally: in a firewall, router, mail server, VPN or a system that nobody knew exactly was still on the Internet.

Patch quickly, keep systems up-to-date and know what you have on your network and what is accessible from the internet. With good asset management you can directly assess what affects the organisation and who should act. That's the difference between panic-induced reactions and control-related actions.

One Independent Cyber Security Audit may compare recorded and effectively visible attack surface, patch status and operation of security measures. For organisations under NIS2 and the Dutch Cybersecurity Act, this demonstration also helps to underpin risk management and supplier management.

Cybersecurity law in practice

Sources and deepening

Based on official frameworks and practical implementation

The source pages provide the formal background. Kynexis Information Security translates this information into an executable approach for your organisation, sector and risk profile.

View NCSC-2026-0318 - Vulnerabilities fixed in Citrix NetScaler ADC and NetScaler GatewayView Citrix CTX696939 - Security Bulletin for CVE-2026-19489 and CVE-2026-19490View Security.nl - Critical security leak in Citrix NetScaler actively abused in attacksView Citrix CTX694799 - Steps to Take if NetScaler ADC is Suspected to be Compromised
Independent insightDo you know what is really accessible from the Internet?

An independent Cyber Security Audit will make it visible which systems, configurations and vulnerabilities determine your digital attack surface and whether the security measures are working.

Check out the Cyber Security Audit