CVE-2026-19490
Awaiting Analysis Awaiting Analysis - Queue

Buffer Overflow in Citrix NetScaler ADC and Gateway

Vulnerability report for CVE-2026-19490, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-09-01

Assigner: NetScaler

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-09-01
Generated
2026-09-08
AI Q&A
2026-08-19
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
citrix netscaler_adc From 14.1 (inc) to 73.32 (inc)
citrix netscaler_adc From 13.1 (inc) to 63.21 (inc)
citrix netscaler_gateway From 14.1 (inc) to 73.32 (inc)
citrix netscaler_gateway From 13.1 (inc) to 63.21 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Citrix NetScaler ADC and NetScaler Gateway affecting versions 14.1 through 73.32 and 13.1 through 63.21. The issue has a high CVSS score of 9.3, indicating severe impact with potential for unauthorized access or data breaches.

Detection Guidance

This vulnerability affects Citrix NetScaler ADC and Gateway versions. Detection requires checking the installed version against the affected ranges (ADC: 14.1-73.32, 13.1-63.21; Gateway: same ranges). Use commands like 'show version' on NetScaler CLI or check system logs for version details.

Impact Analysis

The vulnerability may allow remote attackers to gain unauthorized access, execute arbitrary code, or disrupt services. It could lead to data theft, system compromise, or denial of service for affected NetScaler ADC and Gateway devices.

Compliance Impact

The vulnerability in NetScaler ADC and Gateway could potentially lead to unauthorized access or data breaches due to its high CVSS score (9.3), which indicates significant impact on confidentiality, integrity, and availability. This may affect compliance with GDPR (data protection) and HIPAA (healthcare data security) if exploited.

Mitigation Strategies

Update NetScaler ADC and NetScaler Gateway to versions beyond the affected ranges (14.1-73.32 and 13.1-63.21).

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19490. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart