Businesses running Citrix NetScaler for remote access are facing their second serious patch emergency in as many months. A newly tracked flaw, CVE-2026-19490, is a critical authentication bypass affecting NetScaler ADC and NetScaler Gateway appliances configured as a VPN gateway, ICA proxy, CVPN, RDP proxy, or AAA virtual server, scoring 9.3 out of 10 on the severity scale. Citrix patched it on 19 August, but attackers have been actively exploiting unpatched appliances since at least 3 September. The US Cybersecurity and Infrastructure Security Agency added it to its Known Exploited Vulnerabilities list on 9 September, with a remediation deadline of 12 September for US federal systems. That deadline has already passed, which tells you exploitation is live and ongoing, not a theoretical future risk.
This comes only weeks after a separate NetScaler flaw, CVE-2026-3055, prompted an NCSC alert covered on this site back in July. If your business, or your IT provider, runs NetScaler for VPN or remote access, this is now the second time this year you need to check the same appliance.
Check whether you’re exposed
The fix is a version upgrade, not a configuration tweak. Affected NetScaler ADC and Gateway systems need upgrading to 14.1-73.32 or later, 13.1-63.21 or later, or the equivalent FIPS/NDcPP builds. If an IT provider manages your infrastructure, the direct question to ask this week is simple: has our NetScaler estate been patched against CVE-2026-19490, and when was that confirmed, not scheduled. If you manage it yourself, check the installed build number against the versions above before doing anything else.
An authentication bypass on a gateway appliance is particularly dangerous because it can let an attacker in without needing stolen credentials at all, sidestepping the password and MFA hygiene many businesses correctly focus on. That’s what makes an unpatched internet-facing appliance like this worse than an ordinary phishing risk: there’s no employee decision involved for the attacker to exploit, and no amount of staff training closes the gap on its own.
Once inside via a flaw like this, an attacker typically has the same access as a legitimate remote worker, which can mean a direct route to internal file shares, email, and other systems the VPN was built to protect. That’s why speed matters more than usual here: every day an appliance sits unpatched is a day it’s reachable by anyone scanning the internet for exactly this weakness, not just a targeted attacker who’s picked your business specifically.
Build the habit, not just the patch
The pattern worth taking from two NetScaler emergencies in three months is that internet-facing infrastructure needs a standing patch-check routine, not a reactive scramble each time a headline appears. If you don’t currently have a clear answer to “who checks our external-facing systems for critical patches, and how often,” that’s the gap to close, whether that’s a named person, an MSP contract that explicitly covers it, or a monitoring service. KeepSafe’s ongoing monitoring approach exists precisely for businesses that would rather have exposure like this flagged automatically than discover it after the fact.
What to ask if someone else manages your IT
Most SMEs don’t manage their own NetScaler appliances directly; an MSP or IT support contract usually does. That’s fine, but it shifts the question from “have we patched it” to “can our provider prove they patched it, and when.” Ask for the specific build number now in place and the date it was applied, not a reassurance that “we’re on top of it.” A provider managing genuinely current infrastructure will have that answer immediately; one that hesitates is telling you something worth following up on.
The takeaway
CVE-2026-19490 is a critical, actively exploited Citrix NetScaler flaw with a fix available since 19 August. If your business runs NetScaler for remote access, confirm this week, not this month, that it’s been patched to the current builds. And use this as the prompt to set up an ongoing check for exactly this kind of alert, rather than relying on catching the next one in the news.