{"id":"CVE-2026-19490","title":"Vulnerability in NetScaler ADC and NetScaler Gateway.\n\nThis issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.","summary":"Vulnerability in NetScaler ADC and NetScaler Gateway.\n\nThis issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-288"],"vendor":"citrix","product":"netscaler_application_delivery_controller","affected":["netscaler_application_delivery_controller >= 13.1, < 13.1-37.277","netscaler_application_delivery_controller >= 13.1, < 13.1-63.21","netscaler_application_delivery_controller >= 14.1, < 14.1-73.32","netscaler_application_delivery_controller >= 14.1-66.68, <= 14.1-73.32","netscaler_gateway >= 13.1, < 13.1-63.21","netscaler_gateway >= 14.1, < 14.1-73.32"],"patched":["netscaler_application_delivery_controller 14.1-73.32","netscaler_gateway 14.1-73.32"],"published":"2026-08-19","updated":"2026-09-10","sourceUpdated":"2026-09-10T12:48:10.453","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19490","references":[{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939","label":"50a63c94-1ea7-4568-8c11-eb79e7c5a2b5"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-19490","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","in-the-wild","exploit-available","kev"],"exploited":true,"exploitAvailable":true,"ssvc":{"exploitation":"active","automatable":"yes","technicalImpact":"total","timestamp":"2026-08-19T00:00:00+00:00"},"scores":{"nvd":9.8,"cna":9.3},"ingestedAt":"2026-09-13T10:44:37.174Z","epss":0.05597,"epssPercentile":0.9261,"kev":true,"kevDateAdded":"2026-09-09","kevDueDate":"2026-09-12","kevRansomware":false,"exploits":{"github":2,"githubRepos":["https://github.com/TarPeg007/CVE-2026-19490","https://github.com/BishopFox/CVE-2026-19490-check"],"checkedAt":"2026-09-21T15:28:20.137Z"},"slug":"CVE-2026-19490","body":"## Overview\n\nVulnerability in NetScaler ADC and NetScaler Gateway.\n\nThis issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.\n\n## Affected\n\n- `netscaler_application_delivery_controller >= 13.1, < 13.1-37.277`\n- `netscaler_application_delivery_controller >= 13.1, < 13.1-63.21`\n- `netscaler_application_delivery_controller >= 14.1, < 14.1-73.32`\n- `netscaler_application_delivery_controller >= 14.1-66.68, <= 14.1-73.32`\n- `netscaler_gateway >= 13.1, < 13.1-63.21`\n- `netscaler_gateway >= 14.1, < 14.1-73.32`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `netscaler_application_delivery_controller 14.1-73.32`\n- `netscaler_gateway 14.1-73.32`","depth":"hadal","depthScore":80,"depthScoreParts":{"impact":53.9,"likelihood":1.1,"exploitation":25,"ransomware":0},"changes":[{"seq":183316,"id":"CVE-2026-19490","ts":1789355959103,"field":"kev","old":"false","new":"true"},{"seq":183315,"id":"CVE-2026-19490","ts":1789355959103,"field":"epss","old":null,"new":"0.05597"},{"seq":46149,"id":"CVE-2026-19490","ts":1789048274658,"field":"cvss","old":"9.3","new":"9.8"},{"seq":35083,"id":"CVE-2026-19490","ts":1789014714506,"field":"kev","old":"false","new":"true"}]}