Citrix released security updates for NetScaler ADC and NetScaler Gateway to fix two critical vulnerabilities, CVE-2026-19490 and CVE-2026-19489, affecting internet-facing application delivery and remote access infrastructure. CVE-2026-19490 is an authentication bypass flaw with a CVSS v4.0 score of 9.3 that can be exploited remotely by an unauthenticated attacker with low complexity and no user interaction, while CVE-2026-19489 is a memory overflow issue that can lead to service disruption and other unpredictable behavior. Vendor guidance ties both issues to Citrix bulletin CTX696939.
Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, with additional impact noted for NetScaler ADC FIPS before 14.1-73.32 FIPS and 13.1-37.277 FIPS/NDcPP. Finnish authorities and Rapid7 said they were not aware of active exploitation at publication time, but both urged organizations to patch immediately because exposed Citrix edge devices are frequent high-value targets. Citrix also published version-specific remediation guidance and configuration checks to help customers determine whether their deployments meet the prerequisites for exploitation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On August 20, 2026, CERT-SE warned about the critical Citrix NetScaler vulnerability CVE-2026-19490, describing it as remotely exploitable by an unauthenticated attacker when the device is configured as a Gateway. CERT-SE urged organizations to apply Citrix's updates promptly and inspect affected systems for signs of intrusion.
On August 19, 2026, CERT-EU published Security Advisory 2026-010 covering the Citrix NetScaler authentication bypass vulnerability CVE-2026-19490. The advisory added another official government/CSIRT notice for the flaw following Citrix's disclosure.
As of August 19, 2026, Rapid7 said it had not observed exploitation in the wild for CVE-2026-19490. It nevertheless urged organizations to patch affected internet-exposed NetScaler systems on an emergency basis.
At the time of its August 19, 2026 notice, Finland's National Cyber Security Centre said it was not aware of exploitation of the NetScaler flaws. It recommended that organizations install the Citrix updates without delay.
On August 19, 2026, new CVE entries were received for CVE-2026-19489 and CVE-2026-19490 covering NetScaler ADC and NetScaler Gateway affected version ranges. The records included CVSS v4.0 vectors and referenced Citrix support article CTX696939.
On August 19, 2026, Citrix published a security advisory for two NetScaler vulnerabilities: CVE-2026-19490, an authentication bypass flaw, and CVE-2026-19489, a memory overflow issue that can cause service disruption or unpredictable behavior. Citrix provided fixed versions for affected NetScaler ADC, Gateway, FIPS, and NDcPP releases and guidance for identifying configurations that meet exploitation prerequisites.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
19 references tracked. Mallory keeps watching after this page renders.
socprime.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcecert.se
Open sourcekyberturvallisuuskeskus.fi
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcelabs.beazley.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.