First published · Last updated
CVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
CISA reports CVE-2026-19490 as an authentication-bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway that may allow an unauthenticated remote actor to bypass authentication. The advisory instructs stakeholders to apply vendor mitigations and follow CISA BOD 26-04 and Forensics Triage Requirements.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 8/10
- Geographic reach
- 4/10
- Global importance
- 4/10
- Impact magnitude
- 5/10
- Positivity
- 2/10
- Urgency
- 7/10
Why it matters
If unmitigated, the flaw could enable unauthorized remote access to affected NetScaler appliances and requires action per CISA guidance.

