CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Citrix security advisory (AV26-833) - Update 1

unknownknown exploitedpublic exploitCVE-2026-19490CVE-2026-19489
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-833 Date: August 19, 2026 Updated: September 9, 2026 As of August 19, 2026, Citrix is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Version 13.1 prior to 13.1-63.21 Version 14.1 prior to 14.1-73.32 NetScaler ADC FIPS Prior to 14.1-73.32 FIPS NetScaler ADC FIPS and NDcPP Prior to 13.1-37.277 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Update 1 On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-19490 to their Known Exploited Vulnerabilities (KEV) Database. NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 Citrix Security Advisories CISA KEV: CVE-2026-19490

CSIRTS triage

vendor: Citrixproduct: Citrix ADC and Citrix GatewayOtheraffected: ADC 13.1 prior to 13.1-63.21, 14.1 prior to 14.1-73.32, ADC FIPS prior to 14.1-73.32, ADC FIPS and NDcPP prior to 13.1-37.277
What
Vulnerabilities CVE-2026-19489 and CVE-2026-19490 affecting Citrix ADC and Gateway products.
Who is affected
Citrix ADC and Gateway users on specified versions.
Urgency
Unknown; severity not specified in advisory; apply patches when available.
Action
Update to patched versions as indicated: ADC to 13.1-63.21 or 14.1-73.32, FIPS to 14.1-73.32 or 13.1-37.277 respectively.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Citrix ADC and Citrix Gateway

Get an email when a new Citrix ADC and Citrix Gateway advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-09-09
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-833

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-19490coverage & exploitation statusNVD · CVE.org
CVE-2026-19489coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security