## Overview
CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities (KEV) list on September 9, 2026. This vulnerability affects Citrix NetScaler ADC and NetScaler Gateway, specifically versions 14.1 through 73.32 and 13.1 through 63.21. The addition to the KEV list signals a federal deadline for organizations to address this issue.
## Technical Details
The vulnerability involves an authentication bypass through an alternate path or channel. When configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), the NetScaler appliance allows unauthenticated remote threat actors to bypass authentication. This flaw can lead to unauthorized access to sensitive resources.
## Impact
The CVSS score for this vulnerability is 9.3, indicating a critical risk. Successful exploitation can allow attackers to gain unauthorized access to systems and data, potentially leading to data breaches or further compromise of the network.
## Mitigation
Citrix has released patches to address this vulnerability. Organizations using affected versions of NetScaler should apply these updates without delay. Additionally, it is recommended to review configurations and monitor for any unusual access patterns that may indicate exploitation attempts.
CSURFACE Threat Sensor