Security & Threat Intelligence · 19.08.2026, 17:31 UTC
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
| Schweregrad | critical aktiv ausgenutzt (KEV) |
|---|---|
| CVSS | 9.3 |
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | Rapid7 Blog ↗ |
| Veröffentlicht | 19.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad kritisch (CVSS 9.3). Sie wird laut CISA-KEV aktiv ausgenutzt und sollte priorisiert behandelt werden. Betroffene Kennungen: CVE-2026-19490. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
OverviewOn August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges.NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network perimeter. NetScaler ADC provides application delivery, traffic management, load balancing, SSL/TLS offloading, and application security capabilities, while NetScaler Gateway provides secure remote access and VPN functionality. Because these systems are frequently deployed in enterprise DMZs and exposed to the public internet, authentication bypass vulnerabilities affecting Citrix products are nearly always exploited by threat actors.CVE-2026-19490 affects the following systems:NetScaler ADC and NetScaler Gateway 14.1: Versions prior to 14.1-73.32NetScaler ADC and NetScaler Gateway 13.1: Versions prior to 13.1-63.21NetScaler ADC FIPS: Versions prior to 14.1-73.32 FIPSNetScaler ADC FIPS and NDcPP: Versions prior to 13.1-37.277As of August 19, 2026, Rapid7 has not observed evidence that CVE-2026-19490 is being exploited in the wild. However, organizations should prioritize patching affected systems on an emergency basis, since Citrix products are high-value targets that tend to quickly see exploitation in the wild.Mitigation guidanceOrganizations running affected NetScaler ADC or NetScaler …
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- high You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))
- medium The Sequels Are Never As Good, But We're Still In Pain (Citrix NetScaler CVE-2026-3055 Memory Overread)
- high Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)
- high You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)