Skip to main content
Canadian Center cybersecurity — alert·CA·

AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489

Number: AL26-019 Date: September 4, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre is aware of vulnerabilities impacting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) Footnote 1 . In response to the vendor advisory released on August 19, 2026, the Cyber Centre released AV26-833 on August 19, 2026 Footnote 2 . Tracked as CVE-2026-19490 Footnote 3 , this vulnerability is an Authentication Bypass Using an Alternate Path vulnerability (CWE-288) Footnote 4 . The vulnerability may allow a remote, unauthenticated attacker to circumvent authentication controls on NetScaler appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server. Tracked as CVE-2026-19489 Footnote 5 , this vulnerability is a C

Read releases like this the second they cross the wire.

1,200+ feeds from 80+ newswires in one live cockpit — saved searches, instant alerts, AI summaries. 7-day free trial, no card required.

Start the free trial →

Your announcement next? Distribute your press release to the global wires with PPN Source — and track its pickup live on PPN World.

PPN Source →
Shared via PPN World — real-time press release intelligence.