chiprook
← Security
SecurityOctober 10, 2026, 13:00

Citrix NetScaler CVE-2026-19490: second auth bypass in one quarter

CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog on September 9, 2026, with a federal remediation deadline of September 12. NVD rates the Citrix NetScaler authentication bypass 9.8: unauthenticated, no user interaction, full confidentiality and integrity impact. It is the second exploited NetScaler flaw in a month after CVE-2026-8452.

Citrix NetScaler CVE-2026-19490: second auth bypass in one quarter
#Citrix#NetScaler#CISA
Read next
Security

CVE-2026-8452 in Citrix NetScaler: SAML parsing overflow leads to pre-auth RCE

Security

Exploit details for Citrix NetScaler CVE-2026-88772 reveal pre-auth shellcode path

Security

CISA flags exploited NetScaler flaw CVE-2026-88779

Security

Citrix patches NetScaler SAML zero-day exploited in attacks