Knox CVE Database
/
CVE-2026-19490
Critical
9.8

CVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.

Added to the CISA KEV catalog:
September 9, 2026

Overview

NetScaler ADC and NetScaler Gateway contain an authentication bypass flaw that allows an unauthenticated remote attacker to access protected resources without valid credentials. The affected appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server; on builds 14.1-43.56 or later and 13.1-61.28 or later, a SAML action must also be present. Versions in the 14.1 and 13.1 release lines up to and including 73.32 and 63.21 respectively are affected.

Vulnerability details

Affected vendor
Citrix
Affected product
NetScaler
Weakness type (CWE)
CWE-288

CWE-288 describes a condition where an application exposes an alternate code path or channel that reaches protected functionality without passing through the normal authentication gate. In NetScaler's case, the Gateway and AAA virtual server components present such a path. Rather than enforcing authentication uniformly across all request routes, the appliance allows certain request paths to reach protected resources without credential validation. The version-specific preconditions, particularly the SAML action requirement on newer builds, suggest the alternate path is tied to how SAML-based authentication flows are wired into the request-handling pipeline.


An attacker with network access to the Gateway or AAA virtual server interface sends a crafted request that traverses the unprotected alternate path, bypassing credential checks entirely. No prior authentication or account knowledge is required. The result is full authentication bypass, granting the attacker access equivalent to a legitimate authenticated session, with high impact on confidentiality, integrity, and availability of the target system. The precondition that the appliance be reachable from the network and configured in one of the affected roles is the only meaningful barrier to exploitation on older builds; newer builds additionally require a SAML action to be configured.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Inspect the running NetScaler configuration for the strings 'add authentication samlAction' and 'add authentication vserver' or 'add vpn vserver' to confirm whether the appliance meets the preconditions for exploitation before patching is complete.
  • Review NetScaler access logs for authentication-success events on Gateway or AAA virtual server endpoints that have no corresponding credential-submission or SAML-assertion exchange in the session flow, which would indicate a session established without completing the normal auth sequence.
  • Monitor for unexpected session establishment or resource access on VPN or ICA Proxy endpoints originating from source IPs outside expected user populations, particularly where no prior authentication log entry exists for that session.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 12, 2026

Additional hardening

  • Upgrade NetScaler ADC and NetScaler Gateway to 14.1-73.32 or later for the 14.1 release line, and to 13.1-63.21 or later for the 13.1 release line. FIPS and NDcPP builds have separate boundaries; see the vendor advisory listed in References.
  • Restrict network access to Gateway and AAA virtual server interfaces to known user source ranges using perimeter controls or NetScaler responder policies, reducing the pool of hosts that can reach the alternate path.
  • If SAML-based authentication is not operationally required on affected builds, audit and remove SAML action configurations ('add authentication samlAction') to eliminate the precondition on newer builds while patching is scheduled.
  • Treat any NetScaler Gateway or AAA virtual server that is internet-facing and unpatched as potentially compromised; perform forensic triage of session logs and authentication records before returning the appliance to production.

Key dates

Published (NVD)
August 19, 2026
Added to CISA KEV
September 9, 2026
Remediation deadline
September 12, 2026
Last updated
September 10, 2026

References

Frequently asked questions

Does CVE-2026-19490 affect my FedRAMP authorization?

If Citrix NetScaler runs inside your authorization boundary, yes. CVE-2026-19490 is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of September 12, 2026 has already passed. For a FedRAMP-authorized service, an unpatched KEV inside the boundary is a finding. An overdue one is a finding your assessor and sponsoring agency can see right now. Your options are to remediate it immediately or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-19490?

Knox does not patch your Citrix NetScaler deployment. Remediation is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; managing your compliance posture while you do it is not something you have to handle on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. For a CVE like CVE-2026-19490, that means exposure surfaces during routine monitoring rather than only when an assessor flags it at review time, giving your team earlier visibility and more time to act.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-19490's remediation deadline of September 12, 2026 has passed. What happens now?

If CVE-2026-19490 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding out and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship on solid footing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.