CVE-2026-19490
NetScaler ADC/Gateway authentication bypass leading to account takeover (CVSS 9.3, CISA KEV)
- Severity
- critical
- Affected product
- Citrix NetScaler ADC/Gateway
- Affected versions
- Citrix NetScaler ADC/Gateway all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- EPSS
- 3% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-09-10
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Citrix NetScaler ADC/Gateway appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-10. Affected verbatim: ADC 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21; Gateway the same two. THIRD NetScaler row in a row to hit the same wall, and it is worth stating once more because it is a fingerprinting gap, not a triage one: Citrix's fix is a BUILD (14.1-73.32), this appliance's version regex is `NetScaler[^0-9]{0,20}(\d+\.\d+)` and captures `14.1`, and 14.1 is both the affected AND the fixed major.minor - so no `lt`/`le` written from this advisory can separate a patched box from an unpatched one, and any that tried would fire on every patched 14.1 in the field. Advisory observation, which still names the id an assessor keys remediation on. The standing fix is a build-level version source for this fingerprint; logged in docs/backlog.md with the other two rows.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →