Severity Daily

IT and AI security incidents, checked against the primary source

Tag: CVE-2026-19489

  • CISA put a 9.3 NetScaler authentication bypass on a three-day clock; Citrix offers no mitigation and the CVE record does not describe the flaw

    CISA put a 9.3 NetScaler authentication bypass on a three-day clock; Citrix offers no mitigation and the CVE record does not describe the flaw

    CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog on September 9, 2026 with a September 12 deadline; Citrix’s advisory, unchanged since August 19, says nothing about exploitation and lists its mitigations as “None.”

    What happened

    On September 9, 2026, CISA added CVE-2026-19490 to the KEV catalog under the name “Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability.” The catalog entry sets dateAdded to 2026-09-09 and dueDate to 2026-09-12 — a three-day remediation window — and flags forensicTriage as Yes, which adds an obligation to check the asset for evidence of compromise rather than simply patch it. knownRansomwareCampaignUse is recorded as Unknown. The weakness is CWE-288.

    CISA’s own description of the flaw reads: “Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.”

    That sentence is the most detailed public description of what this vulnerability does, and it comes from the agency rather than from the vendor or the CVE record.

    Citrix published the underlying advisory, CTX696939, on August 19, 2026. It covers two flaws. CVE-2026-19489 is described in five words — “Memory overflow vulnerability leading to unpredictable behavior or Denial of Service” — and scored 8.8 on CVSS v4.0, vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:L. CVE-2026-19490 is described in six — “Authentication bypass using an alternate path” — and scored 9.3, vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L. Under the heading for mitigations, the advisory says: “None.”

    The affected and fixed builds are specific. NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.32 are affected, fixed in 14.1-73.32 and later. The 13.1 train is affected before 13.1-63.21, fixed in 13.1-63.21 and later. NetScaler ADC FIPS is affected before 14.1-73.32 FIPS. NetScaler ADC FIPS and NDcPP on the 13.1 train are affected before 13.1-37.277, which is where that train’s fix lands — a lower build number than the mainline 13.1 fix, because the FIPS and NDcPP branches carry their own numbering.

    The advisory as published carries no statement about exploitation in the wild, and the copy retrieved for this story showed no revision note or last-updated date after August 19, 2026.

    Why it matters

    Start with the CVE record, because it is the artifact most organizations will actually consult, and it does not describe the vulnerability. The full text of the description on the NVD record for CVE-2026-19490 is: “Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.”

    There is no verb describing an attack, no mention of authentication, no mention of AAA virtual servers or Gateway configurations. Someone triaging from that record alone learns only that a product is affected in some way. The one field that could have carried the meaning carries a version range instead, and the range itself is wrong in a way that matters operationally. “From 14.1 through 73.32” is not a coherent range — 14.1 is a train and 73.32 is a build within it — and read literally it says that build 14.1-73.32 is inside the affected set. Citrix says 14.1-73.32 is the fix. The same inversion applies to 13.1 and 63.21.

    That is not a pedantic complaint. Scanners and asset inventories consume these ranges. An operator who has already applied 14.1-73.32 and then checks the CVE record has a reasonable chance of concluding the appliance is still exposed, and an operator running an unpatched 13.1 build below 63.21 gets no clear signal of where to go. The vendor advisory is correct and unambiguous; the record built on top of it is neither. On this one, read Citrix.

    The scoring is similarly thin. The only CVSS entry on the record is a v4.0 vector supplied by the Citrix CNA, marked secondary, with no NIST primary score and no v3.1 vector at all. NVD lists the record as “Awaiting Analysis,” published August 19, 2026 and last modified September 1, 2026, and as of this writing it does not yet carry CISA’s cisaExploitAdd or cisaActionDue fields. Organizations whose vulnerability management still keys on CVSS v3.1 base scores will find nothing to key on here. This site has covered the v3.1-versus-v4.0 gap on other vendors’ records; the NetScaler case is a cleaner example than most, because there is no v3.1 score to disagree with.

    Then there is the three-week gap between disclosure and the KEV listing. Citrix shipped fixed builds on August 19 without describing what the bug does beyond six words and without any exploitation language. Three weeks later a US federal agency judged the flaw exploited and gave civilian agencies until Saturday to remediate it. Citrix has not, as of this writing, revised CTX696939 to say the same thing. Both statements can be true — CISA adds entries on evidence it does not always publish, and vendors update advisories on their own timelines — but the practical effect is that the only public authority calling this exploited is the government, and the vendor page a customer is most likely to open still reads like a routine August patch.

    NetScaler is also the wrong product to be vague about. An appliance configured as a Gateway or an AAA virtual server is, by definition, reachable from the internet and sitting in front of authentication for everything behind it. CISA’s description names four such configurations — SSL VPN, ICA Proxy, CVPN, and RDP Proxy — which is useful scoping that the vendor advisory does not provide. Appliances not in one of those roles are, on CISA’s wording, a different risk proposition from ones that are. That distinction only exists in the KEV entry.

    What to do

    Inventory NetScaler ADC and NetScaler Gateway builds and compare against the vendor list, not the CVE record: 14.1-73.32 and later, 13.1-63.21 and later, 14.1-73.32 FIPS and later, and 13.1-37.277 and later on the FIPS and NDcPP branch. Anything below those is unfixed. Because CTX696939 covers CVE-2026-19489 as well, the same upgrade closes the 8.8 memory overflow.

    Prioritize by role first. Any appliance configured as a Gateway — SSL VPN, ICA Proxy, CVPN, or RDP Proxy — or as an AAA virtual server is in the configuration CISA describes as exploitable, and should go first. There is no mitigation to fall back on: Citrix’s advisory says “None,” so the upgrade is the control. Restricting management-interface reachability is worth doing on general principles but does not address a flaw in the Gateway path itself.

    Federal civilian agencies have until Saturday, September 12, 2026, and because the entry carries the forensic-triage flag, patching alone does not discharge it. Everyone else running an internet-facing NetScaler in an affected build should assume the same urgency and check the appliance’s authentication logs for sessions that begin without a preceding authentication event, which is the shape an alternate-path bypass leaves behind.

    Sourcing note

    Checked: Citrix advisory CTX696939 at support.citrix.com for the CVE list, descriptions, CVSS v4.0 vectors, affected and fixed builds, and the mitigation statement; the NVD record for CVE-2026-19490 for description text, scoring, status, and dates; and CISA’s KEV catalog entry.

    cisa.gov returns 403 to automated fetching, so the KEV entry was read from cisagov/kev-data on GitHub, which CISA maintains as a mirror of the cisa.gov/kev data files. The file used is catalog version 2026.09.09, dateReleased 2026-09-09T19:00:50.2591Z.

    Unresolved: CISA does not publish the evidence behind a KEV determination, and Citrix has not confirmed exploitation. The number of affected appliances is not public. The retrieved copy of CTX696939 showed no revision history, so it cannot be stated with certainty that the page has not been amended since August 19, 2026 — only that the version read for this story carried no exploitation language and no later date. NVD had not attached CISA’s KEV fields to CVE-2026-19490 at the time of writing.