Multiple vulnerabilities in Citrix products (20 August 2026)
Multiple vulnerabilities have been discovered in Citrix products. They allow an attacker to cause remote denial of service, security policy bypass and an unspecified security issue by the editor.
CSIRTS triage
- What
- Multiple vulnerabilities in Citrix products enable remote denial of service, security policy bypass, and an unspecified issue.
- Who is affected
- Citrix product customers are affected; specific products and versions not specified.
- Urgency
- Low to moderate urgency pending clarification of the unspecified security issue and affected product scope.
- Action
- Contact Citrix support to identify affected products and versions, then apply relevant patches.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1059/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-194890.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-19490Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 92% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-19489 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19490 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedCitrix Products Multiple Vulnerabilitieshkcert
- unknownexploitedAL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-…cccs
- unknownexploitedCitrix security advisory (AV26-833) - Update 1cccs
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerabilitycisa-kev
- unknownexploitedNCSC-2026-0318 [1.01] [H/H] Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gatewayncsc-nl
- critical[UPDATE] [kritisch] Citrix Systems NetScaler (Gateway und ADC): Mehrere Schwachstellencert-bund
- unknownNCSC-2026-0318 [1.00] [M/M] Vulnerabilities resolved in Citrix NetScaler ADC and NetScaler Gatewayncsc-nl
- criticalexploited2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gatewaycert-eu
- unknownCVE-2026-19490: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 throug…nvd
- unknownCVE-2026-19489: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 throug…nvd
Recent advisories for Citrix products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownexploitedCitrix Products Multiple Vulnerabilitieshkcert · 2026-09-10
- unknownMultiple Vulnerabilities in Citrix Products (July 15, 2026)cert-fr-avis · 2026-07-15
- unknownCitrix Products Multiple Vulnerabilitieshkcert · 2026-07-03
- unknownMultiple vulnerabilities in Citrix products (July 1, 2026)cert-fr-avis · 2026-07-01
- criticalexploitedCVE-2017-6316: Citrix Multiple Products Remote Code Execution Vulnerabilitycisa-kev · 2022-03-25
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans MongoDB (14 septembre 2026)2026-09-14
- unknownVulnérabilité dans CPython (14 septembre 2026)2026-09-14
- unknownMultiples vulnérabilités dans Squid (14 septembre 2026)2026-09-14
- unknownMultiples vulnérabilités dans Microsoft Edge (14 septembre 2026)2026-09-14
- unknownMultiples vulnérabilités dans MISP (14 septembre 2026)2026-09-14