CVE-2026-19489
published 2026-08-19CVE-2026-19489: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through…
PriorityP350high8.8CVSS 4.0
AVNACLATNPRNUINVCLVILVAHSCNSINSALEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.39%
32.2th percentile
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
| netscaler | adc | 13.1 – 63.21 | — |
| netscaler | adc | 14.1 – 73.32 | — |
| netscaler | gateway | 13.1 – 63.21 | — |
| netscaler | gateway | 14.1 – 73.32 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
Citrix Security Bulletin CTX696939
vendor_citrix·CVSS 8.8
CVE-2026-19489 [HIGH] Citrix Security Bulletin CTX696939
Citrix Security Bulletin CTX696939
CVE References: CVE-2026-19489, CVE-2026-19490, CVE-2026-42491, CVE-2026-53565, CVE-2026-53566
Affected Products: Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
Vulnerability in NetScaler ADC and NetScaler Gateway.
ghsa_unreviewed·2026-08-19
CVE-2026-19489 [HIGH] CWE-120 Vulnerability in NetScaler ADC and NetScaler Gateway.
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
No detection rules found.
No public exploits indexed.
Checkpoint
24th August – Threat Intelligence Report
blogs_checkpoint·2026-08-24
CVE-2026-19478 24th August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 24th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment records of more than 1.2 million people – roughly two-thirds of the country’s population – as well as 200,000 organizations. The stolen data included identification numbers, license plates, payment amounts, dates and addresses. Attackers reportedly exploi
Hackernews
Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
blogs_hackernews·2026-08-20·CVSS 8.8
CVE-2026-19489 [HIGH] Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability.
According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess ZTNA Hybrid deployments that use customer-managed NetScaler instances.
It bears noting that the vulnerabilities do not apply to Citrix-managed cloud servi
2026-08-19
Published