On 9 September 2026 the US cybersecurity agency CISA added a critical authentication-bypass flaw in Citrix NetScaler to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies just until 12 September to patch.
Why the flaw is dangerous
Tracked as CVE-2026-19490, the vulnerability is classed as “Authentication Bypass Using an Alternate Path or Channel” (CWE-288) and carries a CVSS 4.0 score of 9.3. No credentials are needed: a remote, unauthenticated attacker can sidestep the login process and reach functionality that would normally require valid access. The bug affects NetScaler ADC and Gateway appliances configured as an AAA or Gateway virtual server — the typical SSL VPN, ICA Proxy, CVPN and RDP Proxy deployments sitting at the network edge.
Active exploitation after public PoC
A working proof-of-concept circulated publicly in early September. Researchers logged dozens of exploitation attempts against honeypot systems between 3 and 8 September. By adding the CVE to KEV on 9 September, CISA confirmed real-world attack activity and set a 12 September remediation deadline under directive BOD 26-04.
Affected versions and the fix
Vulnerable builds include 14.1 releases before 14.1-73.32 and 13.1 releases before 13.1-63.21, with separate fixed builds for FIPS and NDcPP editions. Citrix shipped the updates on 19 August 2026. Administrators should patch internet-facing appliances immediately and, given the KEV warning, hunt for signs of compromise.
Source: CISA – Known Exploited Vulnerabilities Catalog (9 Sept 2026)














