Description
Vulnerability in NetScaler ADC and NetScaler Gateway.

This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Published: 2026-08-19
Score: 9.3 Critical
EPSS: 3.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE identifier refers to a vulnerability affecting the firmware of Citrix NetScaler ADC and Gateway appliances; however, the description does not reveal the precise weakness or exploitation technique. The associated CVSS score of 9.3 indicates a high severity assessment, but because the CVE data is silent about the actual impact, a definitive conclusion such as remote code execution is not stated and can only be presumed as a possibility based on the score.

Affected Systems

The flaw applies to NetScaler ADC versions from 14.1 through 73.32 and 13.1 through 63.21, and to NetScaler Gateway versions in the same ranges. Administrators should verify the firmware version running on their appliances against these ranges.

Risk and Exploitability

The high CVSS score signals a critical threat, and the EPSS score of 3% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no widely reported exploitation to date. The lack of an explicit attack vector in the description means the exact method of compromise is unknown; however, the devices’ typical exposure to external networks suggests that an attacker could potentially target the appliance if a suitable exploitation path is discovered. The vulnerability remains significant simply due to the severity rating and the broad version coverage.

Generated by OpenCVE AI on August 26, 2026 at 14:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest NetScaler ADC and Gateway firmware update referenced in Citrix support article CTX696939.
  • Reboot the appliance to apply the updated firmware.
  • Restrict access to the management interface so that it is reachable only from trusted networks or through a VPN until the update is fully deployed.

Generated by OpenCVE AI on August 26, 2026 at 14:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-288
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-78
CWE-94

Wed, 19 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-78
CWE-94

Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Netscaler
Netscaler adc
Netscaler gateway
Vendors & Products Netscaler
Netscaler adc
Netscaler gateway

Wed, 19 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Title NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NetScaler

Published:

Updated: 2026-08-20T13:22:42.320Z

Reserved: 2026-08-10T17:39:56.668Z

Link: CVE-2026-19490

cve-icon Vulnrichment

Updated: 2026-08-20T13:22:36.586Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T13:17:45.000

Modified: 2026-09-01T21:03:04.987

Link: CVE-2026-19490

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T15:00:07Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel