CVE-2026-19490 is a critical-severity authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway. With a CVSS score of 9.3, it affects appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, under specific version-dependent conditions. Exploitation could allow an attacker to bypass authentication and gain unauthorized access. Citrix has released updates to address this flaw.