GPU VulnDB

Database/Control plane, storage & DevOps

Citrix NetScaler ADC and Gateway: unauthenticated remote compromise of the appliance

CVSS 9.3CVE-2026-19490Control plane, storage & DevOpsKnown exploitedcurated

Impact

Citrix describes only "a vulnerability" in NetScaler ADC and Gateway, but the scoring is unauthenticated, network-reachable, with high confidentiality, integrity and availability impact on the appliance and some spillover to systems behind it, and CISA lists it as exploited in the wild. Where NetScaler fronts a datacenter as the load balancer or the remote-access gateway, an attacker who takes it owns the TLS termination point, the session material for everyone logging in, and a foothold that sits between the internet and the cluster. Affected: ADC and Gateway 14.1 before 73.32 and 13.1 before 63.21. The record carries no technical detail at all - the mechanism, the affected feature and the preconditions are unknown from public data, so treat the exposure as broad until Citrix says otherwise.

Who can reach it

Network, unauthenticated, no user interaction per the CVSS 4.0 vector. The record does not say which virtual server type or feature must be configured, so assume any reachable NetScaler on an affected build is in scope.

What to do

Move to a fixed build per Citrix CTX696939 (14.1-73.32 or later, 13.1-63.21 or later on those branches). This is an appliance image upgrade and reboot rather than a package update: do it one HA node at a time and expect established sessions to drop. Given active exploitation, upgrading is not sufficient on its own - rotate credentials and session secrets the appliance held and review it for persistence, as Citrix has advised for prior exploited NetScaler flaws. Builds outside the two listed branches are end-of-life and get no fix.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.