Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
- CVE-2026-19490Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
9.8 critical · over the network, without login · CISA deadline was 12 Sept
- CVE-2026-8452Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
9.8 critical · over the network, without login · CISA deadline was 29 Aug
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Citrix NetScaler ADC und Gateway: Schwachstelle ermöglicht Codeausführung und DoS
WID-SEC-W-2026-3847 · 9 Oct
- Citrix NetScaler ADC und Gateway: Schwachstelle ermöglicht Denial of Service
WID-SEC-W-2026-3719 · 5 Oct
- Citrix NetScaler ADC und Citrix NetScaler Gateway: Mehrere Schwachstellen
WID-SEC-W-2026-3587 · 29 Sept
- Citrix Systems NetScaler (Gateway und ADC): Mehrere Schwachstellen
WID-SEC-W-2026-2927 · 7 Sept
- Citrix Systems NetScaler ADC und Gateway: Mehrere Schwachstellen
WID-SEC-W-2026-2147 · 27 Aug
Version history & changelog · as detected by patchletter
No releases recorded yet — the source was just added.
An email as soon as a new NetScaler ADC / Gateway version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current NetScaler ADC / Gateway version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/netscaler)https://patchletter.com/badge/netscaler.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).