Vulnerability in NetScaler ADC and Gateway by Citrix
CVE-2026-19489

8.8HIGH

Key Information:

Vendor

Netscaler

Vendor
CVE Published:
19 August 2026

Badges

πŸ“ˆ Score: 388πŸ“° News Worthy

What is CVE-2026-19489?

CVE-2026-19489 is a significant vulnerability identified in the NetScaler Application Delivery Controller (ADC) and Gateway products by Citrix. These products are designed to provide secure and reliable access to applications and services for users while optimizing network traffic and enhancing application performance. The vulnerability affects multiple versions of both the ADC and Gateway, specifically versions ranging from 14.1 to 73.32 and 13.1 to 63.21. If exploited, this vulnerability could allow unauthorized access to sensitive organizational data or lead to the disruption of services. The potential for exploitation emphasizes the need for organizations using these products to promptly address the vulnerability to mitigate associated risks.

Potential impact of CVE-2026-19489

  1. Unauthorized Access: The vulnerability could enable attackers to gain unauthorized access to the NetScaler ADC and Gateway systems, potentially compromising sensitive data and allowing for exploitation of connected environments.

  2. Service Disruption: Exploitations of this vulnerability have the potential to disrupt the services provided by the ADC and Gateway, impacting business continuity and user experience.

  3. Increased Attack Surface: Organizations utilizing affected versions of NetScaler products may find themselves at a heightened risk for further attacks, as the compromised systems can serve as entry points for additional malicious activities, leading to data breaches and loss of critical information.

Affected Version(s)

ADC 14.1 <= 73.32

ADC 13.1 <= 63.21

Gateway 14.1 <= 73.32

News Articles

Citrix urges admins to patch new NetScaler flaws as soon as possible

Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances.

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • πŸ“°

    First article discovered by BleepingComputer

  • Vulnerability published

  • Vulnerability Reserved

.