Citrix security advisory (AV26-833)
Serial Number: AV26-833 Date: August 19, 2026 As of August 19, 2026, Citrix is affected by vulnerabilities in the following products: Citrix ADC and Citrix Version 13.1 prior to or equal to 13.1-63.21 Version 14.1 prior to or equal to 14.1-73.32 Citrix ADC FIPS Prior to 14.1-73.32 FIPS Citrix ADC FIPS and NDcPP Prior to 13.1-37.277 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Citrix ADC and Citrix Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 Citrix Security Advisories
CSIRTS triage
- What
- Vulnerabilities CVE-2026-19489 and CVE-2026-19490 affecting Citrix ADC and Gateway products.
- Who is affected
- Citrix ADC and Gateway users on specified versions.
- Urgency
- Unknown; severity not specified in advisory; apply patches when available.
- Action
- Update to patched versions as indicated: ADC to 13.1-63.21 or 14.1-73.32, FIPS to 14.1-73.32 or 13.1-37.277 respectively.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Citrix ADC and Citrix Gateway
Get an email when a new Citrix ADC and Citrix Gateway advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-833
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-19489 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19490 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- critical2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gatewaycert-eu
- unknownCVE-2026-19490: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 throug…nvd
- unknownCVE-2026-19489: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 throug…nvd
More from Canadian Centre for Cyber Security
- unknownMLflow security advisory (AV26-832)2026-08-19
- criticalOracle Corporation security advisory (AV26-831)2026-08-19
- unknownNVIDIA security advisory (AV26-830)2026-08-19
- unknownAtlassian security advisory (AV26-829)2026-08-19
- unknownApple security advisory (AV26-823) – Update 12026-08-18