NetScaler CVE-2026-19490 Lets Attackers Bypass Authentication 

NetScaler flaws could enable authentication bypass and DoS attacks.

Written By
Ken Underhill
Ken Underhill
Aug 19, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A NetScaler vulnerability could let remote attackers bypass authentication on exposed enterprise gateways without valid credentials. 

Successful exploitation could provide unauthorized access to internal corporate resources. 

Separately, a second NetScaler vulnerability could trigger denial-of-service conditions on affected appliances. 

Key takeaways

  • CVE-2026-19490 is a critical NetScaler authentication bypass with a CVSS score of 9.3 that could allow remote attackers to access protected resources without valid credentials.
  • CVE-2026-19489 is a high-severity memory overflow flaw that could trigger denial-of-service conditions and disrupt network services.
  • NetScaler ADC and Gateway 14.1 and 13.1 are affected, with exploitation requirements varying by software build and configuration.
  • Customer-managed NetScaler deployments require action, while Cloud Software Group has already patched its cloud-managed services and Adaptive Authentication offerings. 

How the NetScaler vulnerabilities work 

Cloud Software Group disclosed two vulnerabilities affecting NetScaler ADC and NetScaler Gateway. 

CVE-2026-19490 is a critical authentication bypass flaw, while CVE-2026-19489 is a high-severity memory overflow vulnerability that can cause denial-of-service (DoS) conditions.  

Both flaws affect network-facing infrastructure, but their exploitation requirements and potential impact differ.

The vulnerabilities affect NetScaler ADC and NetScaler Gateway 14.1 before build 73.32 and 13.1 before build 63.21, including the corresponding FIPS and NDcPP variants. 

Secure Private Access Hybrid deployments that use customer-managed NetScaler appliances are also affected. 

Cloud Software Group has already patched its cloud-managed services and Adaptive Authentication offerings.

Advertisement

CVE-2026-19490 could bypass NetScaler authentication

The more severe flaw, CVE-2026-19490, carries a CVSS score of 9.3 and stems from an authentication bypass through an alternate path. 

This flaw could allow a remote attacker to circumvent authentication controls on vulnerable NetScaler appliances without valid credentials.

CVE-2026-19490 affects appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, as well as authentication, authorization, and auditing (AAA) virtual servers. 

Because these services can act as access points between remote users and internal applications, bypassing authentication could give an attacker unauthorized access to resources that would normally sit behind a trusted security boundary.

CVE-2026-19490 exploitation requirements 

The conditions required for exploitation depend on the NetScaler build. 

On NetScaler 14.1-43.56 and later and 13.1-61.28 and later, a SAML action must be configured for the vulnerability to be exploitable. 

Earlier builds have a broader attack surface because the presence of any Gateway or AAA virtual server configuration is sufficient to meet the vulnerability’s prerequisite conditions.

Administrators should evaluate both the installed NetScaler version and its authentication configuration rather than relying on version information alone to determine whether an appliance meets the conditions for exploitation.

Advertisement

CVE-2026-19489 could cause denial-of-service conditions

The second vulnerability, CVE-2026-19489, carries a CVSS score of 8.8 and stems from improper memory buffer restrictions that can lead to a memory overflow. 

Unlike CVE-2026-19490, this flaw does not bypass authentication; instead, it can affect the availability and stability of vulnerable appliances.

Exploitation requires Session Initiation Protocol Application Layer Gateway (SIP ALG) to be enabled within a Large Scale NAT (LSN) group configuration. 

Under those conditions, the memory overflow vulnerability could cause unexpected appliance behavior or trigger a DoS condition.

CVE-2026-19489 could disrupt network services 

The operational impact could extend beyond the NetScaler appliance itself. 

Organizations that depend on affected systems for traffic management, NAT translation, remote connectivity, or other network services could experience service disruptions if an appliance becomes unavailable.

How to mitigate the NetScaler vulnerabilities 

Because the vulnerabilities affect both authentication and service availability, security teams should address the immediate flaws while strengthening controls around access, segmentation, and monitoring. 

  • Patch affected NetScaler ADC and Gateway appliances and review configurations to determine whether systems are impacted by CVE-2026-19490 or CVE-2026-19489. 
  • Reduce unnecessary external exposure and restrict management interfaces and remote access to trusted networks and approved users.
  • Enforce MFA and default-deny access policies to strengthen authentication and limit access to only required resources.
  • Segment NetScaler appliances from sensitive internal systems to limit lateral movement and reduce the blast radius of a gateway compromise.
  • Monitor and preserve authentication, appliance, firewall, and network logs for unusual access attempts, configuration changes, or service instability.
  • Test incident response plans and use attack simulation tools with scenarios around NetScaler compromise.
Advertisement

Together, these measures can reduce exposure to NetScaler-based attacks while building resilience against future gateway and remote access threats. 

Bottom line

These vulnerabilities highlight the risk of treating remote access infrastructure as an inherently trusted security boundary. 

Security teams should assess which applications, identities, privileged systems, and network segments are reachable through NetScaler and verify that downstream controls can prevent unauthorized access from progressing deeper into the environment. 

This analysis can identify paths where a gateway compromise could enable lateral movement or privilege escalation and help determine where stronger segmentation, access controls, and continuous authentication are needed to contain an attack. 

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.