CVE-2026-19490Critical· 9.8▾ Hadal⚠ Exploited in the wildPoC availableVulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 1.1 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Sep 12, 2026
3.4%
Last analysed / modified upstream
9.3 → 9.8
3.4% → 6.0%
2 GitHub repos (last check)
Added to the CISA catalog on Sep 9, 2026. Federal remediation due Sep 12, 2026. View catalog ↗
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
netscaler_application_delivery_controller >= 13.1, < 13.1-37.277netscaler_application_delivery_controller >= 13.1, < 13.1-63.21netscaler_application_delivery_controller >= 14.1, < 14.1-73.32netscaler_application_delivery_controller >= 14.1-66.68, <= 14.1-73.32netscaler_gateway >= 13.1, < 13.1-63.21netscaler_gateway >= 14.1, < 14.1-73.32Upgrade past the affected range:
netscaler_application_delivery_controller 14.1-73.32netscaler_gateway 14.1-73.32Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-3519Critical· 9.8Unauthenticated remote code execution
CVE-2025-5777High· 7.5Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CVE-2023-4966Critical· 9.4Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
CVE-2019-19781Critical· 9.8An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0
CVE-2026-20079Critical· 10.0A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …
CVE-2019-11634Critical· 9.8Citrix Workspace App before 1904 for Windows has Incorrect Access Control.