VORANT. Threat Intelligence Sign in Get the full feed

Citrix NetScaler ADC/Gateway flaws patched

high vulnerability technology

Citrix patched two NetScaler ADC and Gateway vulnerabilities enabling denial of service and security policy bypass.

CERT-FR issued an advisory covering two vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway products, tracked as CVE-2026-19489 and CVE-2026-19490. The flaws allow an attacker to trigger a remote denial of service, bypass security policy controls, and cause an unspecified security issue as described by the vendor. Affected versions include NetScaler ADC and Gateway builds prior to 13.1-63.21 and 14.1-73.32, as well as FIPS-compliant variants prior to 13.1-37.277 and 14.1-73.32 FIPS.

Citrix released a security bulletin (CTX696939) on August 19, 2026 detailing the issues and providing patched versions. No indicators of active exploitation are mentioned in this advisory; organizations running affected NetScaler ADC or Gateway deployments should apply the vendor-provided fixes referenced in the bulletin as soon as possible.

Mentioned in this report

Vulnerabilities CVE-2026-19489CVE-2026-19490KEV

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1059

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free