Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-19490 2026-09-09

Citrix NetScaler Authentication Bypass (CVE-2026-19490) Added to CISA KEV

"CISA added CVE-2026-19490, a critical authentication-bypass flaw in NetScaler ADC and NetScaler Gateway, to the Known Exploited Vulnerabilities catalog on 2026-09-09 with a three-day remediation deadline."

CISA added CVE-2026-19490, a critical authentication-bypass flaw in NetScaler ADC and NetScaler Gateway, to the Known Exploited Vulnerabilities catalog on 2026-09-09 with a three-day remediation deadline.

What Is It

CVE-2026-19490 is an authentication bypass using an alternate path or channel (CWE-288) in Citrix NetScaler ADC and NetScaler Gateway. When the appliance is configured as an AAA virtual server or as a Gateway, SSL VPN, ICA Proxy, CVPN, or RDP Proxy, an unauthenticated remote threat actor may be able to bypass authentication entirely.

The CVE was published on 2026-08-19 and carries a CVSS 4.0 base score of 9.3 (CRITICAL), vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L. NVD lists the record as "Undergoing Analysis."

Why It Matters

CISA's KEV listing confirms active exploitation. The agency's SSVC decision points rate exploitation as active, automatable as yes, and technical impact as total: meaning attackers can script the attack at scale and fully compromise affected appliances.

The CVSS metrics reinforce this: network attack vector, low complexity, no privileges, no user interaction, and high confidentiality, integrity, and availability impact. NetScaler Gateway and AAA virtual servers are, by design, internet-facing authentication front doors, so a pre-auth bypass hands an attacker whatever sits behind them.

Known ransomware campaign use is listed as Unknown. The KEV entry flags forensic triage as required.

What's Vulnerable

Per the NVD record, affected releases are identified by NetScaler's <release>-<build> build numbering:

Administrators can confirm the running build with show version on the appliance CLI or from the GUI dashboard, and compare it against the build numbers above.

Exposure requires the appliance to be configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy).

Patch Status

Citrix has published security bulletin CTX696939 covering NetScaler ADC and NetScaler Gateway. CISA's required action is to apply mitigations in accordance with vendor instructions, in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. For cloud services, follow applicable BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable.

The due date is 2026-09-12, three days after KEV addition. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines.

Sources