Citrix security advisory (AV26-833) - Update 1
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-833 Date: August 19, 2026 Updated: September 9, 2026 As of August 19, 2026, Citrix is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Version 13.1 prior to 13.1-63.21 Version 14.1 prior to 14.1-73.32 NetScaler ADC FIPS Prior to 14.1-73.32 FIPS NetScaler ADC FIPS and NDcPP Prior to 13.1-37.277 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Update 1 On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-19490 to their Known Exploited Vulnerabilities (KEV) Database. NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 Citrix Security Advisories CISA KEV: CVE-2026-19490
CSIRTS triage
- What
- Vulnerabilities CVE-2026-19489 and CVE-2026-19490 affecting Citrix ADC and Gateway products.
- Who is affected
- Citrix ADC and Gateway users on specified versions.
- Urgency
- Unknown; severity not specified in advisory; apply patches when available.
- Action
- Update to patched versions as indicated: ADC to 13.1-63.21 or 14.1-73.32, FIPS to 14.1-73.32 or 13.1-37.277 respectively.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Citrix ADC and Citrix Gateway
Get an email when a new Citrix ADC and Citrix Gateway advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-833
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-19490Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 93% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-194890.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-19490 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19489 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedCitrix Products Multiple Vulnerabilitieshkcert
- unknownexploitedAL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-…cccs
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerabilitycisa-kev
- unknownexploitedNCSC-2026-0318 [1.01] [H/H] Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gatewayncsc-nl
- critical[UPDATE] [kritisch] Citrix Systems NetScaler (Gateway und ADC): Mehrere Schwachstellencert-bund
- unknownNCSC-2026-0318 [1.00] [M/M] Vulnerabilities resolved in Citrix NetScaler ADC and NetScaler Gatewayncsc-nl
- unknownMultiple vulnerabilities in Citrix products (20 August 2026)cert-fr-avis
- criticalexploited2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gatewaycert-eu
- unknownCVE-2026-19490: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 throug…nvd
- unknownCVE-2026-19489: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 throug…nvd
More from Canadian Centre for Cyber Security
- unknownMikrotik security advisory (AV26-887) – Update 12026-09-11
- criticalAL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-860602026-09-10
- unknownHPE security advisory (AV26-909)2026-09-10
- unknownWebPros security advisory (AV26-908)2026-09-10
- unknownAdobe security advisory (AV26-808) – Update 12026-09-10