Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw Found in Citrix NetScaler VPN and Gateway

A serious security weakness has been found in Citrix NetScaler ADC and Gateway products, which are commonly used for remote access and VPN services. This flaw could allow attackers to bypass login controls, potentially giving unauthorised access to your network. It is important for organisations using these products to act quickly to protect their systems.

20 August 2026

Reference: CVE-2026-19490

1. What is being reported?

A critical vulnerability identified as CVE-2026-19490 affects multiple versions of Citrix NetScaler ADC and Gateway software. This flaw allows attackers to bypass authentication, meaning they could access the system without proper credentials. The issue impacts versions from 13.1 through 73.32.

2. What this means in plain English

If your organisation uses Citrix NetScaler for remote access or VPN, this vulnerability could let attackers get into your network without needing a password. This could lead to data theft, disruption of services, or further attacks on your systems.

3. Could this affect a small business?

Small businesses and charities using Citrix NetScaler ADC or Gateway for remote access or VPN could be at risk. Organisations not using these products or using different remote access solutions are unlikely to be affected.

4. What to do now

  • Check if your organisation uses Citrix NetScaler ADC or Gateway for remote access or VPN.
  • Contact your IT provider or software supplier to confirm if your version is affected and ask about available patches or updates.
  • Apply any security updates or patches provided by Citrix as soon as possible.
  • Review remote access logs for any unusual activity and consider additional monitoring until the issue is resolved.

5. Ask your IT provider

Can you confirm if our Citrix NetScaler ADC or Gateway software is affected by CVE-2026-19490, and what steps are being taken to protect us?

6. Bottom line

If you use Citrix NetScaler for remote access, act quickly to update and secure your systems against this critical vulnerability.

Information based on CISA KEV, NVD, and reputable security reporting.

Back to Vulnerability Briefs