NetScaler ADC and Gateway

CVE-2026-19490: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490

Vulnerability in NetScaler ADC and NetScaler Gateway.

Published

ExploitedYes, in CISA KEVAdded 9 Sept 2026
Ransomware useNot reportedPer CISA
SeverityCRITICALCVSS 4.0 9.3
EPSS23%Chance of exploitation in 30 days
Public exploitNot tracked
FixNot yet

Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.

Affected and fixed versions

Product / branchFixed in
ADC 14.1 to 73.32Upgrade past 73.32; see the advisory
ADC 13.1 to 63.21Upgrade past 63.21; see the advisory
Gateway 14.1 to 73.32Upgrade past 73.32; see the advisory
Gateway 13.1 to 63.21Upgrade past 63.21; see the advisory

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

Vulnerability in NetScaler ADC and NetScaler Gateway.

This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Exploitation

CISA lists this CVE as exploited in the wild since 9 Sept 2026.

Sources

KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.