High severityNVD Advisory· Published Aug 19, 2026· Updated Sep 1, 2026
CVE-2026-19489
CVE-2026-19489
Description
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Affected products
4Patches
Vulnerability mechanics
References
1News mentions
9- Kiteworks & Citrix Incidents Show Challenges of Zero-Day ResponseDark Reading · Oct 2, 2026
- Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilitiesTenable Blog · Sep 27, 2026
- Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in AttacksCyber Security News · Sep 27, 2026
- 24th August – Threat Intelligence ReportCheck Point Research · Aug 24, 2026
- Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, Azure Credential Theft +20 StoriesCyber Security News · Aug 23, 2026
- Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)Help Net Security · Aug 21, 2026
- Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA ServersThe Hacker News · Aug 20, 2026
- Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalerSecurityWeek · Aug 20, 2026
- Critical Citrix NetScaler Flaw Lets Remote Attackers Bypass Authentication Without CredentialsCyber Security News · Aug 19, 2026