Vulnerability in NetScaler ADC and Gateway by Citrix
CVE-2026-19490
Key Information:
Badges
What is CVE-2026-19490?
CVE-2026-19490 is a vulnerability affecting the Citrix NetScaler ADC (Application Delivery Controller) and NetScaler Gateway. These products are designed to optimize application delivery, enhance security, and provide remote access to applications and networks. The vulnerability lies within specific versions of the software, which range from 14.1 through 73.32 and from 13.1 through 63.21. If exploited, this vulnerability can allow attackers to compromise the functionality and security of systems reliant on these products, potentially leading to unauthorized access to sensitive data and systems within an organization. Given the critical role that NetScaler products play in managing application delivery and remote access, organizations utilizing these systems are at significant risk if they do not address this vulnerability.
Potential Impact of CVE-2026-19490
-
Unauthorized Access: The vulnerability could allow attackers to gain unauthorized access to applications and internal networks, leading to potential data breaches. This access could enable them to exfiltrate sensitive information or manipulate systems without detection.
-
Disruption of Services: Exploiting this vulnerability may result in service disruptions or degradation of system performance, impacting business operations and end-user experiences. This can have cascading effects on customer satisfaction and operational efficiency.
-
Increased Risk of Data Breach: With the possibility of attackers gaining entry through vulnerable NetScaler instances, organizations may face an increased risk of data breaches, which can lead to regulatory fines, legal liabilities, and reputational damage. The fallout from such incidents often requires significant resources to address and remediate.
Affected Version(s)
ADC 14.1 <= 73.32
ADC 13.1 <= 63.21
Gateway 14.1 <= 73.32
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian.
4 days ago
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs - Help Net Security
Hereโs an overview of some of last weekโs most interesting news, articles, interviews and videos: Windows 11โs strongest security defenses can be bypassed
2 weeks ago
Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) - Help Net Security
Citrix patched two vulnerabilities in NetScaler ADC and Gateway, including a critical bypass flaw, CVE-2026-19490.
3 weeks ago
References
CVSS V4
Timeline
- ๐
Vulnerability started trending
- ๐ก
Public PoC available
- ๐ฐ
Used in Ransomware
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by Securityweek
Vulnerability published
Vulnerability Reserved