Skip to content
Citrix Products Multiple Vulnerabilities

Citrix Products Multiple Vulnerabilities

Hkcert • September 10, 2026

Multiple vulnerabilities were identified in Citrix Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and security restriction bypass on the targeted system.

CVE-2026-19490 is being exploited in the wild. Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. Hence, the risk level is rated as Medium Risk.

Security Restriction Bypass

System / Technologies affected

NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-73.32

NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.21

NetScaler ADC FIPS BEFORE 14.1-73.32 FIPS

NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.277

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

Vulnerability Identifier

Extracted Entities