20 August 2026
Reference: CVE-2026-19490
1. What is being reported?
A critical vulnerability identified as CVE-2026-19490 affects multiple versions of Citrix NetScaler ADC and Gateway software. This flaw allows attackers to bypass authentication, meaning they could access the system without proper credentials. The issue impacts versions from 13.1 through 73.32.
2. What this means in plain English
If your organisation uses Citrix NetScaler for remote access or VPN, this vulnerability could let attackers get into your network without needing a password. This could lead to data theft, disruption of services, or further attacks on your systems.
3. Could this affect a small business?
Small businesses and charities using Citrix NetScaler ADC or Gateway for remote access or VPN could be at risk. Organisations not using these products or using different remote access solutions are unlikely to be affected.
4. What to do now
- Check if your organisation uses Citrix NetScaler ADC or Gateway for remote access or VPN.
- Contact your IT provider or software supplier to confirm if your version is affected and ask about available patches or updates.
- Apply any security updates or patches provided by Citrix as soon as possible.
- Review remote access logs for any unusual activity and consider additional monitoring until the issue is resolved.
5. Ask your IT provider
Can you confirm if our Citrix NetScaler ADC or Gateway software is affected by CVE-2026-19490, and what steps are being taken to protect us?
6. Bottom line
If you use Citrix NetScaler for remote access, act quickly to update and secure your systems against this critical vulnerability.
Information based on CISA KEV, NVD, and reputable security reporting.