Active Exploitation of Vulnerability in NetScaler ADC and NetScaler Gateway
7 September 2026
Attackers are exploiting a critical vulnerability in NetScaler ADC and NetScaler Gateway. Patch immediately.
Background
NetScaler has released security updates to address multiple vulnerabilities (CVE-2026-19490, CVE-2026-19489) affecting NetScaler ADC and NetScaler Gateway. The vulnerabilities have Common Vulnerability Scoring System (CVSS v4.0) scores of: CVE-2026-19490 at 9.3 and CVE-2026-19489 at 8.8.
Impact
Successful exploitation of these vulnerabilities could lead to the following:
CVE-2026-19490: Allow an unauthenticated attacker to bypass authentication and compromise an affected system, resulting in high impact to confidentiality, integrity, and availability.
CVE-2026-19489: Allow an attacker to trigger a memory overflow, resulting in an unpredictable system behaviour or denial of service.
Known Exploitation
CVE-2026-19490 is reportedly being actively exploited, with a publicly available Proof-of-Concept (PoC) exploit and exploitation attempts observed in the wild.
Affected Products
These vulnerabilities affect the following products:
NetScaler ADC: versions 14.1 through 73.32
NetScaler ADC: versions 13.1 through 63.21
NetScaler Gateway: versions 14.1 through 73.32
NetScaler Gateway: versions 13.1 through 63.21
Users and administrators should refer to the vendor advisory for the full list of affected versions.
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-19490 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-19489 (opens in new tab)
