CVE-2026-19490
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Sep 9, 2026
- US federal agencies must remediate it by Sep 12, 2026 (BOD 22-01)
- First attack observed 15 days after disclosure
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Source: CISA KEV · Sep 9, 2026 Sep 3, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| citrix | netscaler application delivery controller | < 13.1-37.277 |
| citrix | netscaler gateway | < 13.1-63.21 |
Related articles
VulnerabilitiesNetScaler Critical Authentication Bypass: Citrix Urges Immediate Patching
Urgent: Patch NetScaler now to fix authentication bypass flaw CVE-2026-19490. Affected versions and mitigation steps included.
VulnerabilitiesCitrix NetScaler: Exploitation Attempts Target Critical Vulnerability CVE-2026-19490
Attackers target CVE-2026-19490, a NetScaler ADC and Gateway auth bypass. PoC attempts seen from 3 countries. Patch vulnerable AAA, VPN configs now.
VulnerabilitiesFortinet CVE-2025-25249 Exploited at Scale to Install PivotC2 RAT
Attackers exploit Fortinet CVE-2025-25249 RCE flaw at scale, scanning 30,000+ IPs to install PivotC2 RAT on 178 devices for tunneling and data theft.
VulnerabilitiesCritical ScreenConnect Flaw Fuels Worm-Like Attacks Through Active Remote Sessions
CVE-2026-84869 lets attackers execute files via active ScreenConnect sessions in worm-like attacks. Patch clients to 26.6.5.9742 now.
VulnerabilitiesCitrix NetScaler Operators Face Unverified Zero-Day Threat With No Patch or Detection Clues
WatchTowr reports two unpatched NetScaler ADC RCE flaws with no CVE, patch, or IoCs. Learn risks, affected versions, and guidance for operators.
VulnerabilitiesCitrix Patches Two NetScaler Zero-Days After Attackers Breach Unmitigated Systems
Citrix patched CVE-2026-88771 and CVE-2026-88772 (CVSS 9.5) in NetScaler ADC/Gateway after active exploitation. Learn affected versions and fixed builds.
VulnerabilitiesCitrix NetScaler Exploits Turn Edge Appliances Into Root-Level Network Tunnels
Citrix confirms active NetScaler exploits CVE-2026-88771 and CVE-2026-88772 enabling root access, web shells and network tunneling.
VulnerabilitiesNetScaler Intrusions Turn a Gateway Flaw Into Root-Level Network Access
Mandiant links CVE-2026-88772 to NetScaler attacks granting root access, web shells, and internal network tunnels across dozens of orgs.
VulnerabilitiesNetScaler Attack Payloads Aim for Superuser Persistence and CSS-Masked Web Shells
Attackers exploit CVE-2026-88771 on NetScaler to deploy reverse shells, create sec_monitor superuser, steal configs and hide PHP web shells as CSS.
VulnerabilitiesNetScaler Zero-Days Put Patch Speed and Shutdown Advice to the Test
Citrix patched eight NetScaler flaws, including two exploited zero-days, sparking debate over immediate upgrades versus taking systems offline.
VulnerabilitiesNetScaler SAML Deployments Need a Second Upgrade After CVE-2026-88779 Attacks
Citrix fixed NetScaler CVE-2026-88779 SAML memory flaw causing DoS. Check SAML configs and upgrade to 14.1-73.41 or 13.1-64.28 amid active attacks.
This product uses the NVD API but is not endorsed or certified by the NVD.