CISA KEV Alert 10 Sept 2026, 01:32 UTC

CISA Warns of Actively Exploited Citrix NetScaler Auth Bypass

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities (KEV) catalogue on 9 September 2026. The vulnerability affects Citrix NetScaler ADC and NetScaler Gateway. Known as the Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability, it can allow unauthenticated remote attackers to bypass authentication in specific configurations.

The flaw involves an alternate path or channel in NetScaler. It affects appliances configured as an AAA virtual server or as a Gateway providing SSL VPN, ICA Proxy, CVPN or RDP Proxy services. A remote attacker does not need to authenticate to exploit the vulnerability. NVD rates it CVSS 9.3, Critical. The available data does not confirm whether a patch is available.

The KEV listing confirms that attackers are actively exploiting this vulnerability. The data does not identify use in ransomware campaigns. CISA set 12 September 2026 as the remediation deadline for affected Federal Civilian Executive Branch (FCEB) agencies.

CISA requires organisations to apply mitigations in accordance with Citrix’s vendor instructions, while complying with CISA’s BOD 26-04 guidance on prioritising security updates based on risk and its Forensics Triage Requirements. Stakeholders must assess each asset’s internet exposure and follow applicable BOD 26-04 patching guidance for cloud services, or discontinue use of the product if mitigations are unavailable. FCEB agencies are directly subject to this requirement; all organisations should review their exposure.

See the NVD entry for CVE-2026-19490 and CISA’s KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline