CVE-2026-19490
published 2026-08-19CVE-2026-19490: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through…
PriorityP182critical9.3CVSS 4.0
AVNACLATNPRNUINVCHVIHVAHSCLSILSALEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-09-12
Exploited in the wild
EPSS
3.37%
88.0th percentile
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_application_delivery_controller | >= 13.1 < 13.1-37.277 | 13.1-37.277 |
| citrix | netscaler_application_delivery_controller | >= 13.1 < 13.1-63.21 | 13.1-63.21 |
| citrix | netscaler_application_delivery_controller | >= 14.1 < 14.1-73.32 | 14.1-73.32 |
| citrix | netscaler_application_delivery_controller | 14.1-66.68 – 14.1-73.32 | — |
| citrix | netscaler_gateway | — | — |
| citrix | netscaler_gateway | >= 13.1 < 13.1-63.21 | 13.1-63.21 |
| citrix | netscaler_gateway | >= 14.1 < 14.1-73.32 | 14.1-73.32 |
| citrix | xenserver | — | — |
| netscaler | adc | 13.1 – 63.21 | — |
| netscaler | adc | 14.1 – 73.32 | — |
| netscaler | gateway | 13.1 – 63.21 | — |
| netscaler | gateway | 14.1 – 73.32 | — |
CVSS provenance
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.3CRITICAL
cisa9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
cisa·2026-09-09·CVSS 9.3
CVE-2026-19490 [CRITICAL] CWE-288 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Vulnerability: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Affected: Citrix NetScaler
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the p
Citrix
Citrix Security Bulletin CTX696939
vendor_citrix·CVSS 8.8
CVE-2026-19489 [HIGH] Citrix Security Bulletin CTX696939
Citrix Security Bulletin CTX696939
CVE References: CVE-2026-19489, CVE-2026-19490, CVE-2026-42491, CVE-2026-53565, CVE-2026-53566
Affected Products: Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
Vulnerability in NetScaler ADC and NetScaler Gateway.
ghsa_unreviewed·2026-08-19
CVE-2026-19490 [CRITICAL] CWE-288 Vulnerability in NetScaler ADC and NetScaler Gateway.
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
VulnCheck
Authentication Bypass Using an Alternate Path or Channel
vulncheck·2026·CVSS 9.3
CVE-2026-19490 [CRITICAL] Authentication Bypass Using an Alternate Path or Channel
Authentication Bypass Using an Alternate Path or Channel
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Affected: NetScaler ADC
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://previdian.com/CVE-2026-19490
No detection rules found.
No public exploits indexed.
Hackernews
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
blogs_hackernews·2026-09-10·CVSS 9.8
CVE-2026-20079 [CRITICAL] CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
The vulnerabilities are listed below -
CVE-2026-20079 (CVSS score: 10.0) - An authentication bypass vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote atta
Checkpoint
24th August – Threat Intelligence Report
blogs_checkpoint·2026-08-24
CVE-2026-19478 24th August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 24th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment records of more than 1.2 million people – roughly two-thirds of the country’s population – as well as 200,000 organizations. The stolen data included identification numbers, license plates, payment amounts, dates and addresses. Attackers reportedly exploi
Hackernews
Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
blogs_hackernews·2026-08-20·CVSS 8.8
CVE-2026-19489 [HIGH] Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability.
According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess ZTNA Hybrid deployments that use customer-managed NetScaler instances.
It bears noting that the vulnerabilities do not apply to Citrix-managed cloud servi
Rapid7
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
blogs_rapid7·2026-08-19·CVSS 9.3
CVE-2026-19490 [CRITICAL] CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
## Overview
On August 19, 2026, a security advisory was published for CVE-2026-19490 , a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges.
NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network perimeter. NetScaler ADC provides application delivery, traffic management, load balancing, SSL/TLS offloading, and application security capabilities, while NetScaler Gateway provides secure remote access and VPN functionality. Because these systems are frequently deployed in enterprise DMZs and
2026-08-19
Published
2026-09-09
Added to CISA KEV
Exploited in the wild