Description
Vulnerability in NetScaler ADC and NetScaler Gateway.

This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Published: 2026-08-19
Score: 9.3 Critical
EPSS: 7.0% Low
KEV: Yes
Impact: Authentication bypass
Action: Immediate Patch
AI Analysis

Impact

The reported vulnerability affects NetScaler ADC and Gateway firmware. The CVSS score of 9.3 indicates a critical severity. The weakness is characterized by authentication bypass, as denoted by CWE-288, which means an attacker may obtain unauthorized access to the appliance or its management interface. The vulnerability’s exact exploitation technique is not detailed, but it potentially allows operational control of the device.

Affected Systems

The flaw applies to NetScaler ADC versions from 14.1 through 73.32 and from 13.1 through 63.21, and to NetScaler Gateway versions in the same range. Administrators should check the firmware version of their appliances against these ranges.

Risk and Exploitability

The high CVSS score and EPSS score of 7% place this vulnerability in the high‑risk category. It is listed in CISA’s KEV catalog, indicating that it has already been exploited in the wild. While the description does not specify the attack vector, the CWE suggests that an attacker can bypass authentication and potentially gain full control of the appliance. Because the appliance is normally exposed to external networks, access to the vulnerable component is likely reachable, making the exploit feasible; this is inferred from typical deployment scenarios. The risk is compounded by the wide version coverage.

Generated by OpenCVE AI on September 24, 2026 at 18:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the latest NetScaler ADC and Gateway firmware update available from Citrix support article CTX696939.
  • Reboot the appliance after firmware installation.
  • Restrict management interface access to trusted networks or require VPN.

Generated by OpenCVE AI on September 24, 2026 at 18:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Citrix
Citrix netscaler Application Delivery Controller
Citrix netscaler Gateway
CPEs cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
Vendors & Products Citrix
Citrix netscaler Application Delivery Controller
Citrix netscaler Gateway
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 10 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:30:00 +0000


Wed, 09 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-09-09T00:00:00+00:00', 'dueDate': '2026-09-12T00:00:00+00:00'}


Thu, 20 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-288
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-78
CWE-94

Wed, 19 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-78
CWE-94

Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Netscaler
Netscaler adc
Netscaler gateway
Vendors & Products Netscaler
Netscaler adc
Netscaler gateway

Wed, 19 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Title NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


Subscriptions

Citrix Netscaler Application Delivery Controller Netscaler Gateway
Netscaler Adc Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: NetScaler

Published:

Updated: 2026-09-10T03:55:17.040Z

Reserved: 2026-08-10T17:39:56.668Z

Link: CVE-2026-19490

cve-icon Vulnrichment

Updated: 2026-08-20T13:22:36.586Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T13:17:45.000

Modified: 2026-09-10T12:48:10.453

Link: CVE-2026-19490

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T18:45:19Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel