CVE-2026-19489Patch

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 22 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 14 signals
  • Technical details provided in 14 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 7d ago at 6 mentions (2026-08-20); latest day: 3
  • 22 total mentions across 9 days

Deep dive

Activity timeline22 mentions / 9d
02356Mentions · 2026-08-19: 4Mentions · 2026-08-20: 6Mentions · 2026-08-21: 3Mentions · 2026-08-22: 1Mentions · 2026-08-28: 1Mentions · 2026-09-02: 1Mentions · 2026-09-04: 2Mentions · 2026-09-05: 1Mentions · 2026-09-26: 3Active Exploitation · 2026-08-20: 1Active Exploitation · 2026-08-21: 1Patch / Workaround · 2026-08-19: 4Patch / Workaround · 2026-08-20: 5Patch / Workaround · 2026-08-21: 2Patch / Workaround · 2026-08-22: 1Patch / Workaround · 2026-08-28: 1Patch / Workaround · 2026-09-05: 1Technical Details · 2026-08-19: 2Technical Details · 2026-08-20: 6Technical Details · 2026-08-21: 3Technical Details · 2026-08-22: 1Technical Details · 2026-08-28: 1Technical Details · 2026-09-05: 108-1908-2008-2108-2208-2809-0209-0409-0509-26
Signal classification4 categories
Patch
1368.4%
Disclosure
315.8%
General
210.5%
Active Exploitation
15.3%
Referenced assets14 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-194
Disclosure1Patch3
2026-08-206
General1Patch5
2026-08-213
Active Exploitation1Patch2
2026-08-221
Patch1
2026-08-281
Patch1
2026-09-021
General1
2026-09-042
Disclosure2
2026-09-051
Patch1
Full discourse20 posts
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🚨 Citrix NetScaler kullanıcıları dikkat! NetScaler ADC ve NetScaler Gateway'de iki ciddi güvenlik açığı tespit edildi. CVE-2026-19490 — CVSS 9.3 Kimlik doğrulama mekanizmasının atlatılmasına neden olabiliyor. SSL VPN, ICA Proxy, CVPN, RDP Proxy veya AAA vServer olarak kullanılan sistemler risk altında. CVE-2026-19489 — CVSS 8.8 Belirli LSN + SIP ALG yapılandırmalarında DoS'a yol açabiliyor. Etkilenen sistemlerin: • NetScaler 14.1-73.32 veya üzeri • NetScaler 13.1-63.21 veya üzeri sürümlere güncellenmesi öneriliyor. Özellikle internete açık NetScaler Gateway cihazları için güncelleme öncelikli olmalı.

    Post summary

    Citrix disclosed two critical vulnerabilities (CVE‑2026‑19490 and CVE‑2026‑19489) affecting NetScaler ADC/Gateway, detailing authentication bypass and DoS issues, and urged users to patch by upgrading to supported releases.

    01062644
    2.4K followersView on X
  • SOCRadar®@socradar
    Patch

    🚨 Critical NetScaler vulnerabilities patched. Cloud Software Group fixed two flaws affecting customer-managed NetScaler ADC and Gateway deployments: 🔴 CVE-2026-19490 (CVSS 9.3): Authentication bypass affecting certain Gateway and AAA configurations. 🟠 CVE-2026-19489 (CVSS 8.8): Memory overflow causing unpredictable behavior or DoS when SIP ALG is enabled on an LSN group. Patch now: [link] #CyberSecurity #NetScaler #PatchNow

    Post summary

    The post announces patches for two critical NetScaler CVEs, supplying technical details but no exploitation evidence.

    00052783
    7.1K followersView on X
  • Jered Bare@jeredbare

    Is active exploitation of CVE-2026-19489 a zero-day or is this a chained attacked? Obviously it's more of the latter but some of these CVEs have been known since last month. The devil will be in the details about this...keep it close.

    10020647
    759 followersView on X
  • Ferroque Systems Inc.@FerroqueSystems
    Patch

    Critical NetScaler security update: CVE-2026-19489 and CVE-2026-19490 affect certain customer-managed NetScaler ADC and Gateway builds. One may allow authentication bypass. Citrix urges customers to upgrade affected systems as soon as possible. 🔗 https://ferrosys.co/4wBTPVc https://t.co/6D6L65v5J9

    Post summary

    Citrix released a critical update for NetScaler ADC and Gateway to address two authentication bypass CVEs, urging customers to upgrade immediately.

    01020264
    180 followersView on X
  • twittacount@twittaccount_

    @jeredbare If it has to do with CVE-2026-19489 then they would rather suggest to immediately patch than shutting the devices down i guess? But if there are known zero days that are under attack it would be unacceptable that Citrix is not publishing more information.

    10010303
    49 followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na dvě závažné zranitelnosti v Citrix NetScaler ADC a NetScaler Gateway, CVE-2026-19490 a CVE-2026-19489. Zranitelnost CVE-2026-19490 s hodnocením CVSS 9.3 umožňuje neautentizovanému útočníkovi obejít autentizaci v konfiguracích využívajících virtuální servery Gateway nebo AAA a autentizaci SAML. Zranitelnost CVE-2026-19489 s hodnocením CVSS 8.8 spočívá v přetečení paměti a při aktivním SIP ALG v konfiguraci skupiny LSN může způsobit nepředvídatelné chování nebo odepření služby. Úspěšné zneužití může vést k neoprávněnému přístupu, kompromitaci chráněných prostředků a narušení služeb. Dotčeny jsou verze NetScaler ADC a NetScaler Gateway 14.1 před 14.1-73.32 a 13.1 před 13.1-63.21, NetScaler ADC FIPS 14.1 před 14.1-73.32 FIPS a NetScaler ADC FIPS a NDcPP 13.1 před 13.1-37.277, včetně nasazení Secure Private Access Hybrid využívajících zasažené instance. 📌Doporučujeme aktualizovat na verzi 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS nebo 13.1-37.277 podle používané produktové řady, případně na novější podporovanou verzi.

    Post summary

    The tweet announces two severe vulnerabilities in Citrix NetScaler ADC and Gateway, details their technical aspects, and urges readers to apply the provided patch versions to mitigate the risk.

    02000732
    4.3K followersView on X
  • Sami Laiho@samilaiho
    Patch

    NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 #CRITICAL https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939

    Post summary

    The text announces Citrix’s security bulletin for two critical NetScaler CVEs, indicating the existence of a vendor advisory that likely includes patch or mitigation information.

    01010968
    30.6K followersView on X
  • old lazy dev@remote_brain42

    @Zaufana3Strona Z tego co widzę to artykuł na stronie Citrixa na temat CVE-2026-19489 i CVE-2026-19490 nie był aktualizowany od dnia publikacji w sierpniu https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939&articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_19489_and_CVE_2026_19490

    10000277
    123 followersView on X
  • Justin Middler@JustinMiddler
    Patch

    ACSC is on Citrix NetScaler ADC and Gateway. CVE-2026-19489 memory overflow. CVE-2026-19490 auth bypass on gateway/SAML. Patches since 19 Aug. Patch now, or confirm your MSP did. https://support.citrix.com/article/CTX696939

    Post summary

    Citrix NetScaler ADC and Gateway are affected by CVE-2026-19489 and CVE-2026-19490, with patches released since 19 Aug.; the text urges users to apply these patches or confirm MSP actions.

    0000096
    72 followersView on X
  • Centre canadien pour la cybersécurité@centrecyber_ca
    Disclosure

    #CyberAlerte | AL26-019 Le Centre pour la cybersécurité est au courant de vulnérabilités touchant NetScaler ADC (anciennement Citrix ADC) et NetScaler Gateway (anciennement Citrix Gateway). https://www.cyber.gc.ca/fr/alertes-avis/al26-019-vulnerabilites-touchant-citrix-netscaler-adc-netscaler-gateway-cve-2026-19490-cve-2026-19489 https://t.co/DQMw0MSHvv

    Post summary

    The Canadian Cyber Centre releases an alert (AL26‑019) announcing two CVE vulnerabilities (CVE‑2026‑19490 and CVE‑2026‑19489) affecting Citrix NetScaler ADC and Gateway, without providing PoC, exploit, or technical details.

    00000184
    3.7K followersView on X
  • Canadian Centre for Cyber Security@cybercentre_ca
    Disclosure

    #CyberAlert | AL26-019 The Cyber Centre is aware of vulnerabilities impacting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). https://www.cyber.gc.ca/en/alerts-advisories/al26-019-vulnerabilities-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2026-19490-cve-2026-19489 https://t.co/XfCOYlxCsi

    Post summary

    The alert announces the presence of two new CVEs affecting Citrix NetScaler products, but offers no exploitation evidence, mitigation instructions, or technical specifics.

    00000900
    34.0K followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    General

    Critical Citrix NetScaler Vulnerabilities Could Expose Systems to Attack (CVE-2026-19489 and CVE-2026-19490) https://www.systemtek.co.uk/2026/09/critical-citrix-netscaler-vulnerabilities-could-expose-systems-to-attack-cve-2026-19489-and-cve-2026-19490/ via @SystemTek_UK

    Post summary

    The headline references CVE-2026-19489 and CVE-2026-19490 in Citrix NetScaler but provides no substantive detail on the vulnerability, exploit, or mitigation.

    0000086
    1.8K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Citrix NetScaler の脆弱性 CVE-2026-19490/19489 が FIXした:認証バイパスと DoS の恐れ https://iototsecnews.jp/2026/08/20/critical-citrix-netscaler-flaw-allows-attackers-to-bypass-authentication/ NetScaler ADC/Gateway アプライアンスにおいて、認証判定処理およびメモリ制御の脆弱性 CVE-2026-19490/CVE-2026-19489 が発見されました。この不備により、アクセス制御の迂回/任意領域への侵入/サービス停止といった被害が生じる恐れがあります。回避策が存在しないため、対応策としては、最新修正適用済みバージョンへの速やかな更新と設定情報の再評価が求められます。 #Citrix #CVE202619489 #CVE202619490 #NetScaler #Vulnerability

    Post summary

    The article reports the discovery of Citrix NetScaler authentication bypass and DoS vulnerabilities (CVE‑2026‑19490/19489) and urges immediate patching and configuration review as the primary mitigation.

    00000136
    511 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical Citrix NetScaler vulnerabilities CVE-2026-19490 & CVE-2026-19489 now pose major auth bypass and DoS risk. Whether you're using ADC, Gateway, or FIPS/NDcPP variants—exposed builds include 14.1-before-73.32 & 13.1-before-63.21. Check SAML actions, AAA vservers & SIP-ALG configs. Patch is urgent—don’t wait till exploitation hits your network. #NetScaler #Citrix #Vulnerability #AuthBypass #ZeroTrust #Cybersecurity https://thedailytechfeed.com/urgent-citrix-netscaler-vulnerabilities-allow-auth-bypass-and-dos/

    Post summary

    The tweet announces critical Citrix NetScaler vulnerabilities (CVE‑2026‑19490/19489) that allow authentication bypass and denial of service, highlights affected build ranges, and urges immediate patching to prevent possible exploitation.

    0000093
    658 followersView on X
  • NCX Group Security@ncxgroup
    Patch

    Citrix patched two critical NetScaler flaws. CVE-2026-19490 is a CVSS 9.3 pre-auth bypass — no credentials, no user interaction required. CVE-2026-19489 is an 8.8 memory overflow. AWS/Azure/GCP images were not yet updated at publication. Patch now. Rotate credentials. Kill active sessions. Hunt for prior access. https://f.mtr.cool/ajxakpshhp

    Post summary

    Citrix has issued patches for two critical NetScaler flaws (CVE‑2026‑19490: pre‑auth bypass, CVSS 9.3; CVE‑2026‑19489: memory overflow, CVSS 8.8). The message urges users to patch, rotate credentials, kill active sessions, and hunt for prior access.

    00000110
    9.9K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-19490 to bypass SAML authentication on NetScaler Gateway appliances, then moving laterally through unsegmented networks. Runtime segmentation helps limit blast radius when perimeter controls fail. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/citrix-netscaler-cve-2026-19490-cve-2026-19489-vulnerabilities-august-2026

    Post summary

    The report confirms that attackers are actively exploiting CVE‑2026‑19490 to bypass SAML authentication on Citrix NetScaler Gateway appliances and move laterally within unsegmented networks.

    0000075
    1.9K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Citrix flags urgent NetScaler patching for CVE-2026-19490 and CVE-2026-19489, which can enable auth bypass and denial of service on specific setups. CISA still tracks prior Citrix flaws in KEV. #Citrix #NetScaler #CISA https://www.hendryadrian.com/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible/ https://t.co/mNrBDWCFyx

    Post summary

    Citrix urges admins to urgently patch NetScaler vulnerabilities CVE‑2026‑19490/19489 that permit authentication bypass and denial‑of‑service attacks; there is no evidence of active exploitation or PoC.

    00000209
    4.6K followersView on X
  • Adam@seoscottsdale
    Patch

    3/4 💥 Also moving fast: • Medusa RaaS hit 500+ critical orgs (CISA/FBI/HHS joint, Aug 19) • Citrix NetScaler CVE-2026-19490 (auth bypass) + CVE-2026-19489 – upgrade to 14.1-73.32 / 13.1-63.21 today • Windows IKE double-free RCE (CVE-2026-33824) – KEV, UDP 500/4500 exposed = game over 4/4 ✅ Action checklist in full article below. Bookmark + share with your SOC. What’s your #1 patch priority today? Drop it 👇

    Post summary

    The post highlights active exploitation of multiple high‑impact CVEs and stresses immediate patching, urging organizations to prioritize the listed upgrades.

    0000074
    12.4K followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Urgent alert: a severe authentication bypass vulnerability (CVE-2026-19490) has been patched in Citrix NetScaler ADC/Gateway. If you use SSL VPN, AAA vservers, or SAML actions, check your version (pre-14.1-73.32 or 13.1-63.21 could be exposed), verify your VPN or AAA configuration, and enable Global Deny Lists now. Other critical fix CVE-2026-19489 involves SIP ALG & LSN settings. Global mitigations are available. #Security #VPN #Citrix #NetScaler #AuthBypass #ZeroTrust #NetScaler #Citrix #Vulnerability #AuthBypass #Security #VPN #CVE #ZeroTrust https://thedailytechfeed.com/critical-netscaler-flaw-lets-attackers-bypass-authentication/

    Post summary

    The tweet alerts users that a serious authentication bypass vulnerability (CVE‑2026‑19490) in Citrix NetScaler ADC/Gateway has been patched, and it provides guidance on checking versions and applying a Global Deny List mitigation.

    00000104
    652 followersView on X
  • Xavier Rivera@XavierRiveraX
    Patch

    Citrix patches two new NetScaler ADC/Gateway flaws: CVE-2026-19490, an unauthenticated auth bypass on AAA virtual servers with SAML Action configs, and CVE-2026-19489, a SIP ALG memory overflow causing denial of service. Neither is confirmed exploited yet, but 22,000+ ADC and roughly 1,800 Gateway instances remain exposed online, per Shadowserver. Patch to 14.1-73.32 or 13.1-63.21.

    Post summary

    Citrix issued patches for two NetScaler ADC/Gateway vulnerabilities, providing specific update versions, while noting no confirmed exploitation yet but many exposed instances remain online.

    0000082
    597 followersView on X

Explore more