Abstrakter Code als Symbol fuer eine Sicherheitsluecke

Citrix NetScaler Under Attack: CISA Flags Exploited Authentication Bypass (CVE-2026-19490)

On 9 September 2026 the US cybersecurity agency CISA added a critical authentication-bypass flaw in Citrix NetScaler to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies just until 12 September to patch.

Why the flaw is dangerous

Tracked as CVE-2026-19490, the vulnerability is classed as “Authentication Bypass Using an Alternate Path or Channel” (CWE-288) and carries a CVSS 4.0 score of 9.3. No credentials are needed: a remote, unauthenticated attacker can sidestep the login process and reach functionality that would normally require valid access. The bug affects NetScaler ADC and Gateway appliances configured as an AAA or Gateway virtual server — the typical SSL VPN, ICA Proxy, CVPN and RDP Proxy deployments sitting at the network edge.

Active exploitation after public PoC

A working proof-of-concept circulated publicly in early September. Researchers logged dozens of exploitation attempts against honeypot systems between 3 and 8 September. By adding the CVE to KEV on 9 September, CISA confirmed real-world attack activity and set a 12 September remediation deadline under directive BOD 26-04.

Affected versions and the fix

Vulnerable builds include 14.1 releases before 14.1-73.32 and 13.1 releases before 13.1-63.21, with separate fixed builds for FIPS and NDcPP editions. Citrix shipped the updates on 19 August 2026. Administrators should patch internet-facing appliances immediately and, given the KEV warning, hunt for signs of compromise.

See also  OpenVPN 2.7.7 Patches Seven Security Flaws

Source: CISA – Known Exploited Vulnerabilities Catalog (9 Sept 2026)

Leave a Comment

Your email address will not be published. Required fields are marked *

Mastodon
Scroll to Top