NetScaler ADC exploited in the wild RCE (CVE-2026-19490)
CVE-2026-19490
CVE-2026-19490: NetScaler ADC and Gateway 14.1/13.1 remote code execution exploited in the wild (CVSS 9.3). Update to 14.1-73.32 or 13.1-63.21 now.
Actively exploited in the wild - CVE-2026-19490 is a critical remote code execution flaw in NetScaler ADC and NetScaler Gateway 14.1 through 73.32 and 13.1 through 63.21 that grants unauthenticated attackers code execution on the appliance. CISA has added it to the Known Exploited Vulnerabilities catalog; update to 14.1-73.32 or 13.1-63.21 immediately.
Overview
CVE-2026-19490 is a network-reachable code execution vulnerability in Citrix NetScaler ADC (application delivery controller) and NetScaler Gateway (remote access gateway). The affected ranges are ADC 14.1 through 73.32 and 13.1 through 63.21, and Gateway 14.1 through 73.32 and 13.1 through 63.21. With a CVSS score of 9.3, the flaw is reachable over the network, requires no authentication, no user interaction, and has low attack complexity. An attacker who can reach the management or gateway interface can execute arbitrary code on the appliance.
Because these devices sit at the network edge, they are high-value targets. NetScaler Gateway frequently terminates VPN and remote access sessions, and ADC often fronts production applications. A compromise here can expose session traffic, allow lateral movement into internal networks, and provide a stable foothold that survives patching of downstream systems.
Impact
Successful exploitation gives an unauthenticated remote attacker code execution in the context of the NetScaler appliance. From there, an attacker can read configuration and secrets, intercept or redirect traffic passing through the device, and pivot toward internal systems that trust the appliance. NetScaler devices have been targeted by extortion-focused actors in past campaigns, and edge appliances are routinely swept for by automated scanners within hours of a public advisory. The EPSS score of 3.4% understates risk for exposed instances, because KEV listing confirms real-world exploitation is already underway.
Remediation and Mitigation
- Update NetScaler ADC and Gateway to 14.1-73.32 or 13.1-63.21 or later. Apply the vendor’s fixed builds without delay given confirmed exploitation.
- Restrict management interface access. Place the management IP behind a firewall or management VLAN, and never expose it to the internet.
- Limit Gateway and ADC virtual servers to only the ports and networks that require them.
- Review logs for unexpected command execution, new accounts, or anomalous outbound connections from the appliance before and after patching.
- If you cannot patch immediately, isolate affected instances at the network layer and monitor closely.
Organizations that suspect compromise should treat the appliance as untrusted and rotate credentials and certificates stored on it. For context on similar edge-device incidents, see our security news coverage and breach reports for post-incident analysis.
Security Insight
NetScaler has now appeared in the KEV catalog more than once, following the pattern seen with CitrixBleed in 2023, which suggests that edge appliances remain the weakest link in perimeter defense and that attackers treat them as reusable infrastructure. The speed from disclosure to confirmed exploitation also reinforces that patch windows for internet-facing systems are measured in hours, not weeks. For defenders, this is a reminder that management interfaces deserve the same monitoring rigor as production endpoints, since a single unpatched appliance can undo years of internal hardening.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150....
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10....
Mitigation bypass in the Networking: HTTP component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9....
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an a...