← All CVEs NewScan detects
criticalKEV

CVE-2026-19490

NetScaler ADC/Gateway authentication bypass leading to account takeover (CVSS 9.3, CISA KEV)

Severity
critical
Affected product
Citrix NetScaler ADC/Gateway
Affected versions
Citrix NetScaler ADC/Gateway all versions before the fix
CISA KEV
Listed as a known exploited vulnerability
EPSS
3% chance of exploitation in the next 30 days
Added to NewScan
2026-09-10
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Citrix NetScaler ADC/Gateway appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-10. Affected verbatim: ADC 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21; Gateway the same two. THIRD NetScaler row in a row to hit the same wall, and it is worth stating once more because it is a fingerprinting gap, not a triage one: Citrix's fix is a BUILD (14.1-73.32), this appliance's version regex is `NetScaler[^0-9]{0,20}(\d+\.\d+)` and captures `14.1`, and 14.1 is both the affected AND the fixed major.minor - so no `lt`/`le` written from this advisory can separate a patched box from an unpatched one, and any that tried would fire on every patched 14.1 in the field. Advisory observation, which still names the id an assessor keys remediation on. The standing fix is a build-level version source for this fingerprint; logged in docs/backlog.md with the other two rows.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →