---
title: "NetScaler Security Alert: BC Business Checklist · Jeyki Security"
description: "Use this owner-friendly checklist to confirm whether your business uses an affected NetScaler appliance, who will patch it, and what evidence to request."
url: "https://jeyki.ca/guides/netscaler-security-alert-bc-business-checklist"
---

1.  [Home](https://jeyki.ca/)
2.  [Guides](https://jeyki.ca/guides)
3.  NetScaler security alert: what BC businesses should ask their IT provider

Remote Access

# NetScaler security alert: what BC businesses should ask their IT provider

Use this owner-friendly checklist to confirm whether your business uses an affected NetScaler appliance, who will patch it, and what evidence to request.

Published

September 13, 2026

Updated

September 13, 2026

Author

Ashwin C.

![Six dark ventilation gates under warm lights, with one slightly open gate revealing cyan light](https://jeyki.ca/generated/netscaler-remote-access-checklist.jpg)

**If your business uses NetScaler ADC or NetScaler Gateway, ask the administrator responsible for it to check the September security alert now.** If you do not know whether you use either product, send the product names to your IT provider. You do not need to diagnose the vulnerability yourself.

The Canadian Centre for Cyber Security updated [alert AL26-019](https://www.cyber.gc.ca/en/alerts-advisories/al26-019-vulnerabilities-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2026-19490-cve-2026-19489) on **September 9, 2026**. It reports that CVE-2026-19490, an authentication-bypass vulnerability, was added to CISA’s Known Exploited Vulnerabilities catalogue that day. The alert recommends emergency patching of affected systems and checking for suspicious activity. Its fixed-build table covers the relevant product branches.

This is a product-specific issue, not evidence that every BC business is affected or that your business has been breached. The immediate business task is to establish ownership, applicability and a documented response.

## Start with one question: do we use this product?

Ask whoever operates your remote-access or application-access systems to check the inventory for **NetScaler ADC** and **NetScaler Gateway**, including their former Citrix product names. Ask about systems managed on your behalf as well as equipment you own.

Avoid assuming that a familiar login page identifies the underlying infrastructure. A useful answer names the product and the person or provider responsible for maintaining it. If neither product is present, record that finding and who checked it. There is no reason to buy a new security product because of this alert alone.

## Send your IT provider this checklist

Request a short written response covering these five points:

1.  **Inventory:** Which relevant appliances support our business, and who owns the response for each one?
2.  **Applicability:** What installed build and configuration were checked against the current advisory? If an appliance is not affected, what is the basis for that conclusion?
3.  **Change plan:** If action is required, who will perform it, when will it happen, and what business access could be interrupted?
4.  **Verification:** What evidence will show the change completed successfully and normal business access still works?
5.  **Follow-up:** Who will assess possible prior unauthorized access, and how will they escalate any suspicious findings?

Ask the administrator to use the current official advisory and vendor instructions rather than a version number copied from a social post. The Cyber Centre’s alert links the vendor bulletin and compromise-response guidance. Product branches and configurations differ, so this page deliberately does not supply a universal upgrade command.

## Make the response workable for the business

Before an agreed change, identify which teams need remote access and nominate a business contact who can confirm normal work resumes. Ask your provider to explain its change safeguards and recovery plan in plain language. Keep a record of the responsible person, agreed timing and completion evidence.

Do not treat a vague “updates are automatic” reply as the end of the conversation. Ask whether that statement covers this specific appliance and advisory. Equally, do not ask an employee to experiment with appliance settings simply to obtain an answer faster.

A completed software update and an investigation into earlier access are different deliverables. Ask for both statuses rather than accepting one general “resolved” label. If the provider finds suspicious activity, request its incident-response plan and a clear account of what is known, what remains uncertain and who is handling the next steps.

## Turn the check into a reusable record

Keep a simple register with the system name, business purpose, technical owner, maintenance provider and date of the last verified review. The next product-specific alert then becomes a short applicability check rather than a search for who manages what.

If ownership or the wider security baseline is unclear, Jeyki’s [Internal Security Review](https://jeyki.ca/services/internal-security-review) can help examine an agreed scope and identify gaps. Appliance remediation and any incident-response work need their own explicitly agreed scope; this guide does not promise emergency vendor support.

For the broader business baseline, see [how AI is changing cybersecurity](https://jeyki.ca/guides/how-ai-is-changing-cybersecurity). The useful lesson is accountability: know which systems you depend on and who verifies that important fixes reach them.

_Checked September 13, 2026 against the Cyber Centre’s September 9 update. This guide is a business coordination checklist, not a replacement for the current vendor advisory or appliance-specific instructions._

* * *

Sources

-   [NetScaler security alert AL26-019, updated September 9, 2026 - Canadian Centre for Cyber Security](https://www.cyber.gc.ca/en/alerts-advisories/al26-019-vulnerabilities-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2026-19490-cve-2026-19489)

* * *

Related services

-   [Internal Security Review](https://jeyki.ca/services/internal-security-review)

* * *

Have a specific situation in mind?

[Discuss your needs](https://jeyki.ca/contact)
