Citrix NetScaler CVE-2026-19490: second auth bypass in one quarter
CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog on September 9, 2026, with a federal remediation deadline of September 12. NVD rates the Citrix NetScaler authentication bypass 9.8: unauthenticated, no user interaction, full confidentiality and integrity impact. It is the second exploited NetScaler flaw in a month after CVE-2026-8452.
- CVE-2026-19490 scores 9.8 on CVSS 3.1 and was added to KEV on September 9, 2026
- Federal remediation deadline is September 12, 2026
- CVE-2026-8452 in NetScaler ADC and Gateway was added to KEV on August 26
- The bypass yields a session the gateway treats as legitimate, with no cryptanalysis
Read next
Security