Description
Vulnerability in NetScaler ADC and NetScaler Gateway.

This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Published: 2026-08-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE designates a high‑severity flaw in Citrix NetScaler ADC and NetScaler Gateway firmware that involves improper buffer handling (CWE-120). The description does not disclose the precise mechanism or exploitation conditions, but the CVSS score of 8.8 signals a significant potential impact if the flaw is leveraged. The EPSS score of 0.00345 indicates a low exploitation probability, and the issue is not listed in the CISA KEV catalog, indicating that the likelihood of exploitation is unknown but the severity warrants rapid attention.

Affected Systems

Advisory covers Citrix NetScaler ADC firmware ranges from version 14.1 through 73.32 and from 13.1 through 63.21, and NetScaler Gateway firmware ranges from 14.1 through 73.32 and from 13.1 through 63.21.

Risk and Exploitability

With a CVSS score of 8.8 the vulnerability is classified as high severity and could enable significant adverse effects on confidentiality, integrity, or availability if exploited. Because the description does not specify an attack vector, it remains uncertain whether flaw is remote or local. The EPSS score of 0.00345 indicates a low estimated exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, but the high severity indicates that the flaw should be treated with priority.

Generated by OpenCVE AI on August 21, 2026 at 04:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the most recent Citrix firmware or security patch for the affected NetScaler ADC and NetScaler Gateway appliances as released by the vendor.
  • If an upgrade cannot be performed immediately, restrict inbound administrative traffic to trusted IP addresses so that only authorized personnel can reach management interfaces.
  • Continuously monitor NetScaler appliance logs and network activity for anomalous configuration changes, and maintain an incident response plan ready to deploy if compromise indicators arise.

Generated by OpenCVE AI on August 21, 2026 at 04:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title High‑Severity Vulnerability in Citrix NetScaler ADC and Gateway
Weaknesses CWE-284

Thu, 20 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title High‑Severity Vulnerability in Citrix NetScaler ADC and Gateway
Weaknesses CWE-284

Thu, 20 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Potential Remote Vulnerability in Citrix NetScaler ADC and Gateway
Weaknesses CWE-284

Wed, 19 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Potential Remote Vulnerability in Citrix NetScaler ADC and Gateway
Weaknesses CWE-284

Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Netscaler
Netscaler adc
Netscaler gateway
Vendors & Products Netscaler
Netscaler adc
Netscaler gateway

Wed, 19 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NetScaler

Published:

Updated: 2026-08-20T13:36:36.529Z

Reserved: 2026-08-10T17:39:54.968Z

Link: CVE-2026-19489

cve-icon Vulnrichment

Updated: 2026-08-20T13:36:33.695Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T13:17:44.870

Modified: 2026-09-01T21:03:04.987

Link: CVE-2026-19489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T04:30:09Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')