A CVSS 9.3 authentication bypass in NetScaler, no exploitation yet, and every reason to treat that as temporary
2026-08-21Security
CVE-2026-19490 lets a remote unauthenticated attacker walk past authentication on NetScaler appliances configured as a gateway or AAA virtual server. Nothing has been seen in the wild. Rapid7's advice is to patch on an emergency basis anyway, and NetScaler's history is the argument.