# Citrix Urges Immediate Patching of Critical NetScaler Vulnerabilities

*Published August 21, 2026*
*Source: [https://www.securityweek.com/exploitation-expected-for-critical-authentication-bypass-patched-in-citrix-netscaler/](https://www.securityweek.com/exploitation-expected-for-critical-authentication-bypass-patched-in-citrix-netscaler/)*

## Executive Summary

Citrix has issued critical patches for vulnerabilities in NetScaler ADC and Gateway, including a severe authentication bypass flaw. These vulnerabilities pose a significant risk to enterprise systems, and organizations are advised to apply the updates immediately.

## Article

Citrix has released urgent patches for two vulnerabilities found in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw. This severe vulnerability, identified as CVE-2026-19490 with a CVSS score of 9.3, can be exploited by remote attackers without any user interaction. It affects NetScaler appliances configured as gateways or AAA virtual servers. Citrix's advisory specifies that several versions of NetScaler ADC and Gateway are impacted, and the company has provided updates to address the vulnerabilities. The affected versions include 14.1-43.56 and later, 14.1-66.68-FIPS and later, and several others. The fixes for this critical issue and a related high-severity memory overflow flaw are available in versions 14.1-73.32 and 13.1-63.21, among others.

Cybersecurity firm Rapid7 highlights the critical nature of these vulnerabilities due to NetScaler's prominent role in enterprise networks, often positioned at or near the network perimeter. They emphasize the importance of promptly patching these systems as they are high-value targets for attackers. While there are currently no reports of active exploitation, Rapid7 anticipates that threat actors may soon target these vulnerabilities due to the accessibility of vulnerable NetScaler devices in enterprise environments.

Citrix also advises customers using Secure Private Access Hybrid deployments to upgrade their NetScaler instances to the recommended builds. With the potential for significant compromise if left unpatched, organizations are urged to prioritize these updates as part of their emergency response measures.
