← Back to Feed

Citrix Products Multiple Vulnerabilities

CVE-2026-19490

September 10, 2026 · HKCERT · Severity: HIGH

Multiple critical vulnerabilities have been disclosed affecting Citrix products, with CVE-2026-19490 confirmed as actively exploited in the wild. The flaws impact Citrix Application Delivery Controller (ADC), Citrix Gateway, and Citrix Virtual Apps and Desktops, potentially allowing attackers to execute arbitrary code or gain unauthorized access to sensitive systems. Citrix has released security updates addressing these vulnerabilities, and organizations are strongly advised to prioritize patching, particularly for Internet-facing Citrix appliances. Security teams should also review access logs for signs of exploitation and ensure network segmentation limits exposure of Citrix management interfaces.

Key Takeaways

  • Multiple vulnerabilities have been identified in Citrix NetScaler ADC and Gateway products, with CVE-2026-19490 confirmed under active exploitation in the wild.
  • Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, which can be exploited for security restriction bypass and DoS.
  • CVE-2026-19490 is an authentication bypass vulnerability using an alternate path or channel, allowing attackers to circumvent security controls on Citrix appliances.
☕ Buy a Coffee