Vulnerability in NetScaler ADC and Gateway by Citrix
CVE-2026-19490

9.3CRITICAL

Key Information:

Vendor

Netscaler

Vendor
CVE Published:
19 August 2026

Badges

๐Ÿ”ฅ Trending now๐Ÿ“ˆ Trended๐Ÿ“ˆ Score: 2,960๐Ÿ’ฐ Ransomware๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC๐Ÿ“ฐ News Worthy

What is CVE-2026-19490?

CVE-2026-19490 is a vulnerability affecting the Citrix NetScaler ADC (Application Delivery Controller) and NetScaler Gateway. These products are designed to optimize application delivery, enhance security, and provide remote access to applications and networks. The vulnerability lies within specific versions of the software, which range from 14.1 through 73.32 and from 13.1 through 63.21. If exploited, this vulnerability can allow attackers to compromise the functionality and security of systems reliant on these products, potentially leading to unauthorized access to sensitive data and systems within an organization. Given the critical role that NetScaler products play in managing application delivery and remote access, organizations utilizing these systems are at significant risk if they do not address this vulnerability.

Potential Impact of CVE-2026-19490

  1. Unauthorized Access: The vulnerability could allow attackers to gain unauthorized access to applications and internal networks, leading to potential data breaches. This access could enable them to exfiltrate sensitive information or manipulate systems without detection.

  2. Disruption of Services: Exploiting this vulnerability may result in service disruptions or degradation of system performance, impacting business operations and end-user experiences. This can have cascading effects on customer satisfaction and operational efficiency.

  3. Increased Risk of Data Breach: With the possibility of attackers gaining entry through vulnerable NetScaler instances, organizations may face an increased risk of data breaches, which can lead to regulatory fines, legal liabilities, and reputational damage. The fallout from such incidents often requires significant resources to address and remediate.

Affected Version(s)

ADC 14.1 <= 73.32

ADC 13.1 <= 63.21

Gateway 14.1 <= 73.32

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Critical Citrix NetScaler auth bypass now leveraged in attacks

Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian.

4 days ago

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs - Help Net Security

Hereโ€™s an overview of some of last weekโ€™s most interesting news, articles, interviews and videos: Windows 11โ€™s strongest security defenses can be bypassed

2 weeks ago

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) - Help Net Security

Citrix patched two vulnerabilities in NetScaler ADC and Gateway, including a critical bypass flaw, CVE-2026-19490.

3 weeks ago

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐Ÿ“ˆ

    Vulnerability started trending

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ’ฐ

    Used in Ransomware

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by Securityweek

  • Vulnerability published

  • Vulnerability Reserved

.