Serial Number: AV26-833
Date: August 19, 2026
Updated: September 9, 2026
As of August 19, 2026, Citrix is affected by vulnerabilities in the following products:
- NetScaler ADC and NetScaler
- Version 13.1 prior to 13.1-63.21
- Version 14.1 prior to 14.1-73.32
- NetScaler ADC FIPS
- Prior to 14.1-73.32 FIPS
- NetScaler ADC FIPS and NDcPP
- Prior to 13.1-37.277
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Update 1
On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-19490 to their Known Exploited Vulnerabilities (KEV) Database.