NetScaler ADC/Gateway CVE-2026-19490 on CISA KEV (due 2026-09-12); exploited since 3 Sep
Cloud Software Group bulletin CTX696939 (19 August 2026, Critical) covers an authentication bypass using an alternate path in customer-managed NetScaler ADC and NetScaler Gateway. CVSS v4.0 9.3. It applies when the appliance is a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server; on some later 14.1/13.1 builds only when a SAML action is also configured. Not Citrix-managed cloud. No workaround. Patch to 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, or 13.1-37.277 FIPS/NDcPP, as applicable. Secure Private Access Hybrid using customer-managed NetScaler also needs those builds. BleepingComputer (4 September 2026) reports Previdian honeypot sensors saw requests matching a public PoC on 3 September from three source IPs geolocated to Australia, the United States and Germany — evidence of exploitation attempts, not confirmed successful compromise of production systems. The Centre for Cybersecurity Belgium also warned of exploitation attempts the same week. Citrix’s August bulletin had not yet flagged active exploitation. WA SOC advisory 20260907003 (7 September 2026, TLP:CLEAR) covers CVE-2026-19490 at CVSS 9.3 for the same build floors, and reports no exploitation on Western Australian Government networks at the time of writing. Distinct from CVE-2026-8452 on this desk. NEW 9–10 September 2026: CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog on 9 September 2026 (due 12 September 2026 for FCEB under BOD 26-04, including forensic triage requirements). SecurityWeek (10 September) summarises ongoing exploitation since at least 3 September after a public PoC, matching earlier Previdian sensor notes. Patch floors unchanged: 14.1-73.32 / 13.1-63.21 and FIPS mates.
- Product
- NetScaler ADC and NetScaler Gateway (customer-managed)
- Versions
- 14.1 before 14.1-73.32; 13.1 before 13.1-63.21; ADC FIPS before 14.1-73.32 FIPS; ADC FIPS/NDcPP before 13.1-37.277
- CVSS
- (CVSS 4.0, Cloud Software Group)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L - Exploited in Australia?
- unknown
- Patch to
- 14.1-73.32; 13.1-63.21; 14.1-73.32 FIPS; 13.1-37.277 FIPS/NDcPP
Primary: Citrix CTX696939 · Vendor: Cloud Software Group (vendor) · CVE: CVE-2026-19490, CVE-2026-8452 · WA SOC 20260907003 (7 Sep 2026; CVE-2026-19490)
