CVE-2026-19490
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
- Published Aug 19, 2026
- CVSS 9.3 critical
- 23.2% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
Affected software
In the news
- Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response Dark Reading ·
- Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug SecurityWeek ·
- CISA orders feds to patch exploited Citrix flaws by Wednesday BleepingComputer ·
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation The Hacker News ·
- Critical vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products Australian Cyber Security Centre ·
- Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway CERT-EU ·