Security Advisory
CVE-2026-19490: CISA Warns of Active Attacks on a Second Critical Citrix NetScaler Flaw
CISA added CVE-2026-19490, a critical authentication bypass in Citrix NetScaler ADC and Gateway, to its Known Exploited Vulnerabilities catalog on September 9, 2026. It is a separate, unrelated flaw from the NetScaler bug we covered in August.
Citrix published security bulletin CTX696939 on August 19, 2026, disclosing two vulnerabilities in NetScaler ADC and NetScaler Gateway. The more severe of the two, CVE-2026-19490, is an authentication bypass using an alternate path or channel, carrying a CVSS v4.0 base score of 9.3. A companion flaw, CVE-2026-19489, is a memory overflow that can cause denial of service, rated 8.8. At the time of disclosure, Citrix did not report active exploitation of either flaw, and security firm Rapid7 stated it had "not observed evidence that CVE-2026-19490 is being exploited in the wild" as of that date, according to Citrix's bulletin and Rapid7's advisory.
That changed within two weeks. Vulnerability intelligence firm Previdian reported that its NetScaler sensors detected requests matching a public proof-of-concept exploit for CVE-2026-19490 beginning September 3, 2026, originating from three distinct source IP addresses geolocated to Australia, the United States, and Germany. Previdian founder Ryan Dewhurst was careful about what that evidence does and does not show: "Our current assessment is that this provides evidence of exploitation attempts, but it does not confirm successful compromise of real-world systems," he said, according to BleepingComputer. CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026, listing a September 12, 2026 due date for federal civilian agencies to remediate under Binding Operational Directive 26-04, per CISA's own catalog entry. Rapid7 updated its advisory as recently as September 11 to state that organizations "should remediate these issues on an urgent basis, outside of normal patching cycles."
Not the Same Flaw We Covered in August
If your organization already patched the Citrix NetScaler flaw we wrote about last month, CVE-2026-8452, do not assume this covers you. CVE-2026-19490 is a separate vulnerability with a separate root cause, disclosed on a different date, in a different bulletin. CVE-2026-8452 was a pre-authentication heap buffer overflow in SAML message parsing that Citrix originally described as a denial-of-service bug before researchers proved it reached full remote code execution. CVE-2026-19490 is an authentication bypass: Citrix's bulletin describes it as reachable when a NetScaler appliance is configured as a Gateway virtual server or as an AAA (Authentication, Authorization, and Auditing) virtual server, the configuration used for SSL VPN access, ICA proxy, Citrix Virtual Private Network (CVPN), or RDP proxy sessions. Both fixes ship in the same patched builds, 14.1-73.32 or later and 13.1-63.21 or later (with matching FIPS and NDcPP builds), so an organization that upgraded for one flaw is very likely already protected against the other, but the two should be tracked and documented as separate findings, not treated as a single patch event.
What the Vulnerability Affects, and Who Is Exposed
NetScaler ADC and NetScaler Gateway are the appliances many businesses rely on to give employees and contractors secure remote access into internal systems. Citrix's bulletin lists no mitigation or workaround for either flaw beyond upgrading to a fixed build. Security researchers monitoring internet-wide scans, cited by BleepingComputer, reported more than 22,000 NetScaler ADC instances and nearly 1,700 NetScaler Gateway instances reachable from the public internet, with no visibility into how many of those have already applied the fix.
What It Means for Your Obligations
Confirm your NetScaler build number against the fixed releases, 14.1-73.32 or later, or 13.1-63.21 or later; FIPS and NDcPP customers should confirm the matching FIPS/NDcPP build numbers in Citrix's bulletin. If your appliance is configured as a Gateway or AAA virtual server for remote access and it has not been upgraded since August 19, 2026, treat this as an emergency patch rather than a routine one, since Citrix has published no interim workaround.
If a Gateway or AAA virtual server on your NetScaler has been reachable from the public internet at any point since early September, review authentication logs for activity you cannot account for, and consider engaging incident response support if anything looks unfamiliar. A confirmed authentication-bypass attempt against an internet-facing remote-access appliance is exactly the scenario that turns into a deeper compromise if it goes unnoticed.
Extend the same question to any managed service provider or IT vendor that operates remote-access infrastructure on your behalf: ask for the exact NetScaler build number and the date it was patched, not a general assurance that everything is up to date.
For businesses subject to the FTC Safeguards Rule or the HIPAA Security Rule, a remote-access gateway is core infrastructure your written risk assessment and technical safeguards are supposed to cover. The FTC Safeguards Rule requires nonbanking financial institutions to maintain a documented program that includes vulnerability monitoring under 16 CFR 314.4(d)(2), though institutions maintaining customer information on fewer than 5,000 consumers are exempt from that specific written risk-assessment and periodic vulnerability-testing requirement under 16 CFR 314.6, and HHS Office for Civil Rights guidance is explicit that identifying and remediating known, actively exploited vulnerabilities in network infrastructure is part of the HIPAA risk analysis obligation.
Cyber One Solutions can help confirm your exposure through our IT and security assessments, which inventory internet-facing infrastructure like this one, and our managed cybersecurity service, which keeps remote-access appliances patched and monitored on a documented schedule.
Sources
- Citrix Security Bulletin CTX696939: NetScaler ADC and NetScaler Gateway Security Update
- CISA Known Exploited Vulnerabilities Catalog: CVE-2026-19490
- Rapid7: ETR, CVE-2026-19490 Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
- BleepingComputer: Hackers target critical Citrix NetScaler auth bypass in attacks
- Help Net Security: Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)
- Federal Trade Commission: FTC Safeguards Rule, What Your Business Needs to Know
- HHS OCR: January 2026 Cybersecurity Newsletter
