Critical severity9.8CISA KEVNVD Advisory· Published Aug 19, 2026· Updated Sep 10, 2026
CVE-2026-19490
CVE-2026-19490
Description
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: 14.1 through 73.32, 13.1 through 63.21
- Range: 14.1 through 73.32, 13.1 through 63.21
- Range: 14.1 through 73.32, 13.1 through 63.21
Patches
Vulnerability mechanics
References
2- support.citrix.com/support-home/kbsearch/articlenvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
18- Hackers Hit NetScaler Zero-Days Before Citrix PatchedGovInfoSecurity · Sep 29, 2026
- Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the PlugSecurityWeek · Sep 28, 2026
- Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilitiesTenable Blog · Sep 27, 2026
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active ExploitationThe Hacker News · Sep 27, 2026
- Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in AttacksCyber Security News · Sep 27, 2026
- CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in AttacksCyber Security News · Sep 10, 2026
- Critical NetScaler Vulnerability Exploited in AttacksSecurityWeek · Sep 10, 2026
- CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch DeadlineThe Hacker News · Sep 10, 2026
- Netscaler CVE-2026-19490 Zero-Day Added to CISA KEV Under Active ExploitationVypr Intelligence · Sep 9, 2026
- 24th August – Threat Intelligence ReportCheck Point Research · Aug 24, 2026
- Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, Azure Credential Theft +20 StoriesCyber Security News · Aug 23, 2026
- Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgsHelp Net Security · Aug 23, 2026
- Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)Help Net Security · Aug 21, 2026
- Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA ServersThe Hacker News · Aug 20, 2026
- Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalerSecurityWeek · Aug 20, 2026
- Critical Citrix NetScaler Flaw Lets Remote Attackers Bypass Authentication Without CredentialsCyber Security News · Aug 19, 2026
- CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayRapid7 Blog · Aug 19, 2026
- CISA Adds Four Known Exploited Vulnerabilities to CatalogCISA Alerts