ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security
Part of a story covered by 5 sources: “CISA adds exploited Citrix NetScaler auth bypass CVE-2026-19490 (CVSS 9.3) to KEV catalog, sets September 12, 2026 federal deadline; Cisco, Fortinet, Chrome flaws added alongside” — merged summary and timeline →

Citrix security advisory (AV26-833) - Update 1

highExploit / PoC exploited in the wildimportance 70CVE-2026-19489CVE-2026-19490
AI summary · glm-5.3-flash

CISA added actively exploited NetScaler flaw CVE-2026-19490 to its KEV catalog; the Canadian Cyber Centre urges Citrix ADC and Gateway admins to patch.

The Canadian Centre for Cyber Security updated advisory AV26-833 covering Citrix NetScaler ADC and Gateway vulnerabilities in versions 13.1 (prior to 13.1-63.21) and 14.1 (prior to 14.1-73.32), plus FIPS builds. On September 9, 2026, CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog, indicating confirmed exploitation. The bulletin also references CVE-2026-19489 from the Citrix NetScaler ADC and Gateway Security Bulletin. Administrators should apply the fixed builds, including 13.1-37.277 and 14.1-73.32 for FIPS variants.

  • CVE-2026-19490 added to CISA KEV on September 9, 2026, signaling active exploitation.
  • Affected: NetScaler ADC/Gateway 13.1 < 13.1-63.21 and 14.1 < 14.1-73.32, plus FIPS builds.
  • Fixed versions include 13.1-63.21, 14.1-73.32, 13.1-37.277 (FIPS), and 14.1-73.32 (FIPS).

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-19489
Unauthenticated Buffer Overflow in Citrix NetScaler ADC and NetScaler Gateway

CVE-2026-19489 is a vulnerability in Citrix NetScaler ADC and NetScaler Gateway classified as a classic buffer overflow (CWE-120), meaning input is copied into a buffer without adequate size checks; it was disclosed by Citrix alongside CVE-2026-19490, the authentication bypass receiving most of the headline attention. Per the CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N), the flaw is reachable over the network by an unauthenticated remote attacker with no user interaction, though detailed trigger conditions are not spelled out in the CVE description. The scoring (VC:L/VI:L/VA:H, base 8.8 High) indicates the primary impact is to availability — likely crashes or denial of service on the appliance — with low confidentiality and integrity impact. All organizations running NetScaler ADC or NetScaler Gateway 14.1 releases through build 73.32, or 13.1 releases through build 63.21, fall within the affected ranges. There is no evidence of exploitation so far: the issue is not in CISA KEV, has no known public proof-of-concept, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days (32nd percentile).

Do: Upgrade affected NetScaler ADC and NetScaler Gateway deployments to the fixed builds identified in Citrix's advisory (see AL26-019 and CISA advisory AV26-833 Update 1); affected ranges are 14.1 through build 73.32 and 13.1 through build 63.21. Until patched, limit internet exposure of appliance interfaces and monitor Citrix channels for signs of exploitation. Also verify whether the same appliances are affected by the related CVE-2026-19490 authentication bypass fixed in the same advisory.

8.8<1%
  • Citrix NetScaler ADC (formerly Citrix ADC) 14.1 releases through build 73.32; 13.1 releases through build 63.21
  • Citrix NetScaler Gateway (formerly Citrix Gateway) 14.1 releases through build 73.32; 13.1 releases through build 63.21
mass≈100,000+ internet-exposed NetScaler ADC/Gateway appliances (order-of-magnitude estimate; not all run affected builds)
CVE-2026-19490
Remote Authentication Bypass in Citrix NetScaler ADC and NetScaler Gateway

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability (CWE-288, 'using an alternate path or channel') that an unauthenticated remote threat actor can exploit. The flaw is triggerable when the appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy deployments, allowing the attacker to bypass authentication without valid credentials. A successful bypass could give an attacker access to VPN-protected or AAA-gated resources as an authenticated user; no CVSS score has been published yet. Organizations running affected NetScaler appliances in these configurations are exposed, and affected version ranges are not specified in the available data, so defenders should consult Citrix advisory AL26-019. The flaw was added to CISA's KEV on 2026-09-09, indicating exploitation in the wild; ransomware use is unknown, no public PoC is known, and EPSS assigns a 3.4% probability of exploitation within 30 days (88th percentile).

Do: Prioritize applying vendor fixes or mitigations per Citrix advisory AL26-019 in line with CISA BOD 26-04, focusing first on internet-facing appliances configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy). Until patched, restrict internet exposure and review VPN/AAA authentication logs for signs of unauthenticated access, following CISA's Forensics Triage Requirements if compromise is suspected.

9.36% KEV PoC
  • Citrix NetScaler ADC and NetScaler Gateway
largeon the order of 10,000-100,000 internet-exposed NetScaler ADC/Gateway appliances
Full article114 words · extracted from cyber.gc.ca · click to collapse

Serial Number: AV26-833
Date: August 19, 2026
Updated: September 9, 2026

As of August 19, 2026, Citrix is affected by vulnerabilities in the following products:

  • NetScaler ADC and NetScaler
    • Version 13.1 prior to 13.1-63.21
    • Version 14.1 prior to 14.1-73.32
  • NetScaler ADC FIPS
    • Prior to 14.1-73.32 FIPS
  • NetScaler ADC FIPS and NDcPP
    • Prior to 13.1-37.277

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Update 1

On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-19490 to their Known Exploited Vulnerabilities (KEV) Database.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-833