Vulnerability in NetScaler ADC and Gateway by Citrix
CVE-2026-19490

9.3CRITICAL

Key Information:

Vendor

Netscaler

Vendor
CVE Published:
19 August 2026

Badges

📈 Trended📈 Score: 3,010💰 Ransomware👾 Exploit Exists🟡 Public PoC🦅 CISA Reported📰 News Worthy

What is CVE-2026-19490?

CVE-2026-19490 is a vulnerability affecting the Citrix NetScaler ADC (Application Delivery Controller) and NetScaler Gateway. These products are designed to optimize application delivery, enhance security, and provide remote access to applications and networks. The vulnerability lies within specific versions of the software, which range from 14.1 through 73.32 and from 13.1 through 63.21. If exploited, this vulnerability can allow attackers to compromise the functionality and security of systems reliant on these products, potentially leading to unauthorized access to sensitive data and systems within an organization. Given the critical role that NetScaler products play in managing application delivery and remote access, organizations utilizing these systems are at significant risk if they do not address this vulnerability.

Potential Impact of CVE-2026-19490

  1. Unauthorized Access: The vulnerability could allow attackers to gain unauthorized access to applications and internal networks, leading to potential data breaches. This access could enable them to exfiltrate sensitive information or manipulate systems without detection.

  2. Disruption of Services: Exploiting this vulnerability may result in service disruptions or degradation of system performance, impacting business operations and end-user experiences. This can have cascading effects on customer satisfaction and operational efficiency.

  3. Increased Risk of Data Breach: With the possibility of attackers gaining entry through vulnerable NetScaler instances, organizations may face an increased risk of data breaches, which can lead to regulatory fines, legal liabilities, and reputational damage. The fallout from such incidents often requires significant resources to address and remediate.

CISA has reported CVE-2026-19490

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-19490 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

ADC 14.1 <= 73.32

ADC 13.1 <= 63.21

Gateway 14.1 <= 73.32

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Citrix admins warned to shut down NetScalers over 2 exploited zero-days

Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week.

5 days ago

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline - SwapUpdate

Ravie LakshmananSep 10, 2026Vulnerability / Network Security

3 weeks ago

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

CISA adds three exploited Cisco, Citrix, and Fortinet flaws to KEV, requiring federal agencies to patch by September 12, 2026.

3 weeks ago

References

EPSS Score

7% chance of being exploited in the next 30 days.

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🦅

    CISA Reported

  • 📈

    Vulnerability started trending

  • 🟡

    Public PoC available

  • 💰

    Used in Ransomware

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by Securityweek

  • Vulnerability published

  • Vulnerability Reserved

.