# Citrix NetScaler ADC/Gateway flaws patched

Published: 2026-08-20 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/5ed1abdf-e12b-59cd-b57b-c8d9424aec31/citrix-netscaler-adc-gateway-flaws-patched

> Citrix patched two NetScaler ADC and Gateway vulnerabilities enabling denial of service and security policy bypass.

CERT-FR issued an advisory covering two vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway products, tracked as CVE-2026-19489 and CVE-2026-19490. The flaws allow an attacker to trigger a remote denial of service, bypass security policy controls, and cause an unspecified security issue as described by the vendor. Affected versions include NetScaler ADC and Gateway builds prior to 13.1-63.21 and 14.1-73.32, as well as FIPS-compliant variants prior to 13.1-37.277 and 14.1-73.32 FIPS.

Citrix released a security bulletin (CTX696939) on August 19, 2026 detailing the issues and providing patched versions. No indicators of active exploitation are mentioned in this advisory; organizations running affected NetScaler ADC or Gateway deployments should apply the vendor-provided fixes referenced in the bulletin as soon as possible.

## Mentioned in this report

- Vulnerabilities: CVE-2026-19489, CVE-2026-19490 (KEV)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1059

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5ed1abdf-e12b-59cd-b57b-c8d9424aec31/citrix-netscaler-adc-gateway-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
