Description
Vulnerability in NetScaler ADC and NetScaler Gateway.

This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Published: 2026-08-19
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Citrix NetScaler ADC and Gateway suffer a flaw that, when exploited, may allow an attacker remote privileged actions or significant unauthorized activities. The vulnerability spans multiple product releases from ADC versions 14.1 through 73.32 and from 13.1 through 63.21, as well as the same version ranges for Gateway. The description does not specify the precise mechanism; however, the CVSS score of 8.8 indicates high severity and the potential for significant compromise of the appliance or the network.

Affected Systems

The issue affects all Citrix NetScaler ADC and Gateway appliances within the specified version ranges, namely ADC 14.1‑73.32 and 13.1‑63.21, and Gateway 14.1‑73.32 and 13.1‑63.21. These versions are deployed in data centers worldwide and serve as load‑balancing or secure‑gateway devices.

Risk and Exploitability

The CVSS score of 8.8 classifies this vulnerability as high severity, indicating a significant potential impact. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high severity still demands prompt action. Based on the description, it is inferred that the attack vector is remote, likely through access to the appliance’s management interface, which would allow an adversary to send crafted traffic and gain elevated privileges or conduct unauthorized operations.

Generated by OpenCVE AI on August 19, 2026 at 19:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Citrix firmware or patch for NetScaler ADC and Gateway that addresses the vulnerability as released.
  • If an upgrade cannot be performed immediately, restrict inbound network traffic to the appliance’s management ports to trusted administrators only.
  • Continuously monitor appliance logs and network activity for anomalous authentication attempts or abnormal traffic patterns, and maintain a rapid incident response plan in case compromise is detected.

Generated by OpenCVE AI on August 19, 2026 at 19:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Potential Remote Vulnerability in Citrix NetScaler ADC and Gateway
Weaknesses CWE-284

Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Netscaler
Netscaler adc
Netscaler gateway
Vendors & Products Netscaler
Netscaler adc
Netscaler gateway

Wed, 19 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NetScaler

Published:

Updated: 2026-08-19T12:45:16.660Z

Reserved: 2026-08-10T17:39:54.968Z

Link: CVE-2026-19489

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T13:17:44.870

Modified: 2026-08-19T13:17:44.870

Link: CVE-2026-19489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T19:30:04Z

Weaknesses