NetScaler ADC and Gateway
CVE-2026-19490: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
Vulnerability in NetScaler ADC and NetScaler Gateway.
Published
ExploitedYes, in CISA KEVAdded 9 Sept 2026
Ransomware useNot reportedPer CISA
SeverityCRITICALCVSS 4.0 9.3
EPSS23%Chance of exploitation in 30 days
Public exploitNot tracked
FixNot yet
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| ADC 14.1 to 73.32 | Upgrade past 73.32; see the advisory |
| ADC 13.1 to 63.21 | Upgrade past 63.21; see the advisory |
| Gateway 14.1 to 73.32 | Upgrade past 73.32; see the advisory |
| Gateway 13.1 to 63.21 | Upgrade past 63.21; see the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Exploitation
CISA lists this CVE as exploited in the wild since 9 Sept 2026.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.