CVE-2026-19490Active Exploitation(citrix / netscaler_application_delivery_controller)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 24 mentions and remains active

Immediate actions

  • Patch citrix netscaler_application_delivery_controller systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-12. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-288

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netscaler_application_delivery_controller
  • netscaler_gateway

Threat summary

  • Active exploitation appears in 77 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 183 mentions across 30 observed days

What's happening

  • Active exploitation reported across 77 signals
  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 32 signals
  • Patch or workaround mentioned in 103 signals
  • Technical details provided in 132 signals
  • Disclosure: 24 classified signals
  • Peaked 11d ago at 24 mentions (2026-09-10); latest day: 2
  • 183 total mentions across 30 days

Affected systems

Vendors
Products
netscaler_application_delivery_controllernetscaler_gateway

Deep dive

Activity timeline183 mentions / 30d
06121824Mentions · 2026-08-19: 9Mentions · 2026-08-20: 16Mentions · 2026-08-21: 18Mentions · 2026-08-22: 6Mentions · 2026-08-23: 2Mentions · 2026-08-24: 6Mentions · 2026-08-26: 1Mentions · 2026-08-27: 1Mentions · 2026-08-28: 3Mentions · 2026-08-29: 1Mentions · 2026-09-02: 4Mentions · 2026-09-03: 2Mentions · 2026-09-04: 16Mentions · 2026-09-05: 9Mentions · 2026-09-06: 3Mentions · 2026-09-07: 6Mentions · 2026-09-08: 3Mentions · 2026-09-09: 3Mentions · 2026-09-10: 24Mentions · 2026-09-11: 14Mentions · 2026-09-12: 2Mentions · 2026-09-13: 1Mentions · 2026-09-14: 6Mentions · 2026-09-15: 1Mentions · 2026-09-16: 2Mentions · 2026-09-17: 2Mentions · 2026-09-24: 2Mentions · 2026-09-26: 11Mentions · 2026-09-27: 7Mentions · 2026-09-28: 2PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-24: 1PoC Mentioned / Linked · 2026-09-02: 2PoC Mentioned / Linked · 2026-09-03: 2PoC Mentioned / Linked · 2026-09-04: 3PoC Mentioned / Linked · 2026-09-05: 3PoC Mentioned / Linked · 2026-09-06: 1PoC Mentioned / Linked · 2026-09-07: 2PoC Mentioned / Linked · 2026-09-08: 3PoC Mentioned / Linked · 2026-09-09: 1PoC Mentioned / Linked · 2026-09-10: 3PoC Mentioned / Linked · 2026-09-11: 3PoC Mentioned / Linked · 2026-09-12: 2PoC Mentioned / Linked · 2026-09-13: 1PoC Mentioned / Linked · 2026-09-14: 2PoC Mentioned / Linked · 2026-09-16: 1PoC Mentioned / Linked · 2026-09-17: 1Exploit Tool / Code · 2026-09-02: 2Exploit Tool / Code · 2026-09-03: 1Exploit Tool / Code · 2026-09-06: 1Exploit Tool / Code · 2026-09-11: 1Exploit Tool / Code · 2026-09-14: 1Exploit Tool / Code · 2026-09-17: 1Active Exploitation · 2026-08-20: 1Active Exploitation · 2026-08-21: 1Active Exploitation · 2026-08-24: 1Active Exploitation · 2026-08-29: 1Active Exploitation · 2026-09-03: 1Active Exploitation · 2026-09-04: 13Active Exploitation · 2026-09-05: 7Active Exploitation · 2026-09-06: 2Active Exploitation · 2026-09-07: 6Active Exploitation · 2026-09-08: 2Active Exploitation · 2026-09-09: 2Active Exploitation · 2026-09-10: 18Active Exploitation · 2026-09-11: 10Active Exploitation · 2026-09-12: 2Active Exploitation · 2026-09-13: 1Active Exploitation · 2026-09-14: 6Active Exploitation · 2026-09-15: 1Active Exploitation · 2026-09-16: 1Active Exploitation · 2026-09-17: 1Patch / Workaround · 2026-08-19: 6Patch / Workaround · 2026-08-20: 11Patch / Workaround · 2026-08-21: 14Patch / Workaround · 2026-08-22: 5Patch / Workaround · 2026-08-23: 2Patch / Workaround · 2026-08-24: 5Patch / Workaround · 2026-08-26: 1Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-08-28: 3Patch / Workaround · 2026-08-29: 1Patch / Workaround · 2026-09-02: 1Patch / Workaround · 2026-09-03: 1Patch / Workaround · 2026-09-04: 8Patch / Workaround · 2026-09-05: 7Patch / Workaround · 2026-09-06: 3Patch / Workaround · 2026-09-07: 3Patch / Workaround · 2026-09-08: 2Patch / Workaround · 2026-09-10: 15Patch / Workaround · 2026-09-11: 5Patch / Workaround · 2026-09-12: 2Patch / Workaround · 2026-09-13: 1Patch / Workaround · 2026-09-14: 3Patch / Workaround · 2026-09-15: 1Patch / Workaround · 2026-09-16: 1Patch / Workaround · 2026-09-17: 1Technical Details · 2026-08-19: 6Technical Details · 2026-08-20: 16Technical Details · 2026-08-21: 17Technical Details · 2026-08-22: 6Technical Details · 2026-08-23: 2Technical Details · 2026-08-24: 5Technical Details · 2026-08-26: 1Technical Details · 2026-08-27: 1Technical Details · 2026-08-28: 3Technical Details · 2026-08-29: 1Technical Details · 2026-09-02: 2Technical Details · 2026-09-04: 12Technical Details · 2026-09-05: 8Technical Details · 2026-09-06: 3Technical Details · 2026-09-07: 4Technical Details · 2026-09-08: 3Technical Details · 2026-09-09: 1Technical Details · 2026-09-10: 18Technical Details · 2026-09-11: 11Technical Details · 2026-09-12: 2Technical Details · 2026-09-13: 1Technical Details · 2026-09-14: 4Technical Details · 2026-09-15: 1Technical Details · 2026-09-16: 1Technical Details · 2026-09-17: 1Technical Details · 2026-09-24: 1Technical Details · 2026-09-27: 108-1908-2208-2608-2909-0409-0709-1009-1309-1609-2609-28
Signal classification5 categories
Active Exploitation
7244.2%
Patch
5634.4%
Disclosure
2414.7%
General
84.9%
PoC
31.8%
Referenced assets142 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-199
Disclosure2General1Patch6
2026-08-2016
Disclosure5General1Patch10
2026-08-2118
Active Exploitation1Disclosure4General1Patch12
2026-08-226
Disclosure1Patch5
2026-08-232
Patch2
2026-08-246
Active Exploitation1Disclosure1Patch4
2026-08-261
Patch1
2026-08-271
Patch1
2026-08-283
Patch3
2026-08-291
Active Exploitation1
2026-09-024
Disclosure1General1PoC2
2026-09-032
Patch1PoC1
2026-09-0416
Active Exploitation13Disclosure1General2
2026-09-059
Active Exploitation6General1Patch2
2026-09-063
Active Exploitation2Patch1
2026-09-076
Active Exploitation6
2026-09-083
Active Exploitation1Patch2
2026-09-093
Active Exploitation2Disclosure1
2026-09-1024
Active Exploitation17Disclosure2Patch5
2026-09-1114
Active Exploitation10Disclosure2General1Patch1
2026-09-122
Active Exploitation2
2026-09-131
Active Exploitation1
2026-09-146
Active Exploitation6
2026-09-151
Active Exploitation1
2026-09-162
Active Exploitation1Disclosure1
2026-09-172
Active Exploitation1Disclosure1
2026-09-242
Disclosure1
2026-09-277
Disclosure1
Full discourse20 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-19490 Vendor: NetScaler Product: ADC Description: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. Link: https://github.com/tarpeg007/cve-2026-19490 #dbugs_vuln

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑19490 affecting NetScaler ADC and Gateway has been discovered and made publicly available via a GitHub repository. No patches or evidence of active exploitation are reported.

    223176315.5K
    3.6K followersView on X
  • The Hacker News@TheHackersNews
    Disclosure

    🚨 Critical NetScaler flaw can bypass authentication on certain Gateway and AAA configurations. Citrix patched CVE-2026-19490 (CVSS 9.3). Exposure depends on the NetScaler version and configuration, with SAML required in some cases. More details: https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html

    Post summary

    Citrix NetScaler flaw CVE‑2026‑19490 enables authentication bypass on certain Gateway and AAA configurations, scored CVSS 9.3, and has been patched by the vendor.

    2310621323.5K
    2.4M followersView on X
  • International Cyber Digest@IntCyberDigest
    Patch

    ❗️Citrix has patched a critical authentication bypass in NetScaler ADC and Gateway. CVE-2026-19490 (CVSS 9.3) needs no credentials and no user interaction, only an appliance running Gateway, an AAA vserver or a SAML action. https://t.co/rveh9tlA5C

    Post summary

    Citrix announced a patch for the critical authentication bypass CVE-2026-19490, providing CVSS score and usage conditions while showing no evidence of active exploitation or PoC availability.

    5113661012.4K
    232.4K followersView on X
  • Rapid7@rapid7
    Disclosure

    🚨 On August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting #Citrix NetScaler ADC and #NetScaler Gateway. Stay up to date with the Rapid7 blog: https://r-7.co/4xkBooY https://t.co/ndpUDATGE5

    Post summary

    Rapid7 issued a security advisory for CVE‑2026‑19490, a critical authentication bypass in Citrix NetScaler ADC and Gateway, but no PoC, exploit code, or patch details were given.

    219139196.0K
    126.0K followersView on X
  • Dark Web Informer@DarkWebInformer

    Nothing really to update on this but... - watchTower has confirmed this with national certs. - CVE-2026-19490 is not the vulnerability. - Citrix has remained silent. Shut down if you can. Better safe than sorry.

    014053108.1K
    241.3K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    Update: Critical NetScaler auth-bypass flaw CVE-2026-19490 is seeing exploitation attempts. Previdian logged 10 attempts from six IPs against its sensors as of Sept. 3. The telemetry does not confirm compromise. Citrix has released fixes. Full update: https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html

    Post summary

    CVE-2026-19490, a NetScaler authentication bypass flaw, has seen active exploitation attempts that have been logged but not confirmed to cause compromise, and Citrix has released fixes.

    216149932.8K
    2.4M followersView on X
  • Ryan Dewhurst@ethicalhack3r
    Patch

    🚨 CVE-2026-19490: NetScaler exploitation attempts detected. Our system autonomously added it to Watch 2 weeks ago. An unverified but credible PoC appeared yesterday. Today, 3 IPs across 3 countries sent matching requests to our sensor. Patch now (last week): https://previdian.com/CVE-2026-19490

    Post summary

    CVE‑2026‑19490 has active exploitation attempts detected, a proof‑of‑concept has appeared, and a patch is now available via the provided link.

    31403072.8K
    21.2K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CITRIX NETSCALER — OFFICIAL PATCHES FOR TWO EXPLOITED RCE ZERO-DAYS (CVE-2026-88771 / CVE-2026-88772) Cloud Software Group (Citrix) published security bulletin CTX697096 covering eight NetScaler ADC / NetScaler Gateway flaws, including two critical remote code execution vulnerabilities that the vendor says have been exploited on unmitigated deployments. Lead issues (vendor CVSS v4 Base Score 9.5 each): • CVE-2026-88771 — Improper input validation → unauthenticated remote command execution. Affects ALL NetScaler ADC and NetScaler Gateway deployments, including default configuration (no extra features required). • CVE-2026-88772 — Memory overflow → remote code execution or denial of service when DTLS is enabled (DTLS is enabled by default on VPN virtual servers unless explicitly set to OFF). Fixed builds (install ASAP): • NetScaler ADC / Gateway 14.1-73.37 and later • NetScaler ADC / Gateway 13.1-64.23 and later (13.1) • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later • NetScaler ADC 13.1-FIPS / 13.1-NDcPP 13.1.37.279 and later Also addressed in the same bulletin: CVE-2026-88773 through CVE-2026-88778 (HTTP request smuggling, policy bypass, additional memory overflows, TCP ISN prediction). ⚠️ Analyst Note: This is the official Citrix confirmation + patch set for the weekend’s unpatched NetScaler RCE warnings. Separate from the earlier auth-bypass CVE-2026-19490 (Aug builds 14.1-73.32 / 13.1-63.21 do NOT include these new fixes). Vendor wording: “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” No public attribution, victim count, or full IOC package in the bulletin at publish time. Patching alone does not prove a previously exposed appliance was clean — treat internet-facing units as potentially compromised until forensics say otherwise. CISA had not listed CVE-2026-88771 / CVE-2026-88772 in KEV as of this post (catalog still 2026.09.25). Prefer the Citrix bulletin over secondary media. Official Citrix bulletin (CTX697096): https://support.citrix.com/external/article/CTX697096/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-and-cve-2026-88772.html #Citrix #NetScaler #ZeroDay #RCE #CVE202688771 #CVE202688772 #Vulnerability #CyberSecurity #ThreatIntel #DDW

    0102436.8K
    206.2K followersView on X
  • Blonde Capital@blondecapitalvc

    This is not a brand-new unknown zero-day. The real issue is CVE-2026-19490 — a critical authentication bypass (CVSS 9.3) in NetScaler ADC/Gateway. Citrix disclosed & patched it on Aug 19. It allows unauthenticated remote access when the device is set up as a Gateway or AAA server. Active exploitation started ~Sept 3 after a public PoC. CISA added it to the KEV catalog on Sept 9. Governments/agencies that issued warnings: 🇺🇸 CISA (KEV) 🇨🇦 Canadian Centre for Cyber Security 🇸🇬 CSA Singapore 🇦🇺 ACSC 🇸🇪 CERT-SE 🇳🇱 NCSC-NL The “shut everything down immediately” reports appear to come from private supplier advice (some citing Dutch sources) shared on Reddit. Not confirmed mass official shutdown orders for a fresh zero-day. The race is the point. The patch existed for two weeks before the PoC wave. Once the control layer is public, defenders and attackers are searching the same surface and the first one to operationalize it wins. I talk about how the attack surface is the infrastructure here: https://blondecapital.substack.com/p/the-attack-surface-is-the-infrastructure?r=6lkj9t&utm_campaign=post-expanded-share&utm_medium=web

    6301164.9K
    657 followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。 - CVE-2025-25249 (Fortinet複数製品) - CVE-2026-19490 (Citrix Netscaler) - CVE-2026-87491 (Chromium) - CVE-2026-20079 (Cisco FMC) https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has added four known exploited vulnerabilities—CVE-2025-25249, CVE-2026-19490, CVE-2026-87491, and CVE-2026-20079—to its catalog, indicating they are actively being exploited.

    1101441.3K
    7.8K followersView on X
  • ThreatWire@ThreatWire_
    Patch

    🚨 CRITICAL: CVE-2026-19490 (CVSS 9.3) is a critical NetScaler ADC/Gateway authentication bypass. The flaw allows unauthenticated attackers to bypass authentication through an alternate path, potentially gaining unauthorized access to affected appliances. Citrix has released security updates. Patch immediately if your NetScaler deployment meets the affected configuration requirements. #Citrix #NetScaler #CVE #AuthenticationBypass #CyberSecurity #Infosec

    Post summary

    Citrix announces that CVE-2026-19490, a critical authentication bypass in NetScaler ADC/Gateway, has been patched and urges immediate patching for affected deployments.

    0201222.4K
    1.6K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Disclosure

    🚨 Citrix NetScaler : une faille critique permet de contourner l’authentification. Vos appliances sont-elles à jour ? 👉 Consultez l'article pour comprendre la vulnérabilité et vérifier vos équipements : https://www.it-connect.fr/citrix-netscaler-cve-2026-19490-contournement-authentification/ #Cybersécurité #Citrix https://www.it-connect.fr/citrix-netscaler-cve-2026-19490-contournement-authentification/

    Post summary

    The tweet announces a critical authentication bypass (CVE‑2026‑19490) in Citrix NetScaler appliances and urges users to verify if their devices are updated, without providing exploit code or patch details.

    020721.1K
    11.7K followersView on X
  • National CERT/CC@CERT_UG
    Patch

    🚨 Patch Now | August 24, 2026 Bringing these CVEs to your attention! - Windows TFTP Server (CVE-2026-62893, CVSS 9.8 - SharePoint (CVE-2026-63520, CVSS 9.1) - Citrix NetScaler (CVE-2026-19490, CVSS 9.3): http://cert.ug | #CyberSafeUG #CERTUGCC https://t.co/pZmfJBv2yz

    Post summary

    The post announces three high‑severity CVEs (Windows TFTP Server, SharePoint, Citrix NetScaler) and urges immediate patching.

    03160356
    1.5K followersView on X
  • Group-IB Global@GroupIB

    Citrix NetScaler CVE-2026-19490 is getting hit too. Honeypots saw 56 attempts since early Sept. 36 on Sept 8 alone. Auth bypass in ADC/Gateway when it’s set up as AAA vserver or Gateway. CVSS 9.3. If that’s your config, don’t sit on it.

    120601.0K
    10.0K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-19490: Authentication bypass in Citrix NetScaler ADC and NetScaler Gateway, 9.3 rating ‍🔥 A recently disclosed authentication bypass vulnerability affects customer-managed NetScaler ADC and NetScaler Gateway. The appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server. 👉 https://nt.ls/Ebg2V

    Post summary

    The tweet announces the exposure of an authentication bypass vulnerability (CVE‑2026‑19490) in Citrix NetScaler ADC/Gateway with a high severity score, but provides no evidence of active exploitation, patches, or PoC.

    01062661
    7.7K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Patch

    🚨 Citrix NetScaler kullanıcıları dikkat! NetScaler ADC ve NetScaler Gateway'de iki ciddi güvenlik açığı tespit edildi. CVE-2026-19490 — CVSS 9.3 Kimlik doğrulama mekanizmasının atlatılmasına neden olabiliyor. SSL VPN, ICA Proxy, CVPN, RDP Proxy veya AAA vServer olarak kullanılan sistemler risk altında. CVE-2026-19489 — CVSS 8.8 Belirli LSN + SIP ALG yapılandırmalarında DoS'a yol açabiliyor. Etkilenen sistemlerin: • NetScaler 14.1-73.32 veya üzeri • NetScaler 13.1-63.21 veya üzeri sürümlere güncellenmesi öneriliyor. Özellikle internete açık NetScaler Gateway cihazları için güncelleme öncelikli olmalı.

    Post summary

    Citrix NetScaler users are alerted to two high‑severity vulnerabilities (CVE‑2026‑19490 authentication bypass and CVE‑2026‑19489 DoS) and are urged to apply the recommended security updates to affected firmware versions.

    01062644
    2.4K followersView on X
  • Cyber Kendra@cyberkendra

    UPDATE- Watchtowr have confirmed that this is not CVE-2026-19490 and also said: "We have high confidence in the information, and have verified it with authoratitive sources."

    12031345
    1.5K followersView on X
  • SOCRadar®@socradar
    Patch

    🚨 Critical NetScaler vulnerabilities patched. Cloud Software Group fixed two flaws affecting customer-managed NetScaler ADC and Gateway deployments: 🔴 CVE-2026-19490 (CVSS 9.3): Authentication bypass affecting certain Gateway and AAA configurations. 🟠 CVE-2026-19489 (CVSS 8.8): Memory overflow causing unpredictable behavior or DoS when SIP ALG is enabled on an LSN group. Patch now: [link] #CyberSecurity #NetScaler #PatchNow

    Post summary

    Two critical NetScaler vulnerabilities (CVE-2026-19490 and CVE-2026-19489) have been patched; the post provides CVE details and a patch link but no PoC, exploit tool, or evidence of active exploitation.

    00052783
    7.1K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Patch

    Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) https://www.helpnetsecurity.com/2026/08/21/citrix-netscaler-gateway-cve-2026-19490/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The advisory alerts customers to patch the critical authentication bypass CVE‑2026‑19490 in Citrix NetScaler; no PoC, exploit, or active exploitation details are supplied.

    140201.7K
    195.2K followersView on X
  • ExploitGrid@exploitgrid

    This is separate from the already-known CVE-2026-19490, which was disclosed in August and added to CISA KEV in September. We're monitoring the emerging NetScaler disclosure. 🔎 https://exploitgrid.net

    01041800
    357 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_gateway---

Explore more