CISA has added CVE-2026-19490, a CVSS 9.3 authentication-bypass vulnerability in Citrix NetScaler ADC and Gateway appliances configured as a gateway or AAA virtual server, to its Known Exploited Vulnerabilities (KEV) catalog, SecurityWeek reported. Exploitation in the wild has been confirmed since at least September 3, 2026.
Citrix patched the flaw on August 19, 2026. Under Binding Operational Directive 26-04, federal civilian agencies have a three-day remediation window once a KEV entry is added. The exploitation has been independently corroborated by Rapid7, Belgium’s CCB, and security firm RedLegg.
Why it matters: NetScaler ADC and Gateway appliances sit at the network perimeter of a huge number of enterprises and government agencies, frequently providing VPN and remote-access functionality. An authentication-bypass flaw at this layer is a direct path into internal networks — including those of critical-infrastructure operators — for any attacker who has not yet patched.
Source: SecurityWeek, September 2026; CISA KEV catalog.

Leave a Reply