CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog (dateAdded September 9, 2026) with a federal fix-by of September 12, 2026. The flaw is a critical authentication bypass (CVSS v4.0 9.3) in NetScaler ADC and NetScaler Gateway when configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Citrix’s bulletin CTX696939 (August 19) lists mitigations as None — patch is the control.
SecurityWeek reports exploitation observed since at least September 3, after a public exploit appeared; Previdian / Ryan Dewhurst flagged matching sensor hits across multiple countries. Victim count: Undisclosed; CISA has not published a campaign size. Fixed builds per Citrix: 14.1-73.32+, 13.1-63.21+, plus corresponding FIPS / NDcPP builds. Inventory internet-facing Gateway/AAA appliances and treat KEV as an emergency SLA.
Underwrite sheet — sourced only: CVE-2026-19490 CVSS 9.3 auth bypass; Citrix CTX696939 Aug 19 (mitigations: None); CISA KEV due Sep 12; exploited since ~Sep 3 (SecurityWeek / Previdian). Primary is the Citrix bulletin + CISA KEV entry. Ransomware attribution: none (CISA lists knownRansomwareCampaignUse as Unknown).
