Our automated tracking framework flagged that CISA added CVE-2026-19490 (Citrix NetScaler) to the Known Exploited Vulnerabilities (KEV) catalog on September 14, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.
What CISA Reported
CISA describes the flaw as follows: “Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.”
Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-19490 by September 12, 2026 — a 3-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.
The Details
| CVE | CVE-2026-19490 |
| Vendor / product | Citrix NetScaler |
| Vulnerability | Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability |
| CVSS base score | 9.8 |
| Added to KEV | September 9, 2026 |
| Days public before listing (NVD → KEV lag) | 21 |
| Federal patch deadline | September 12, 2026 |
| Known ransomware use | No |
How This Compares to Citrix’s Track Record
This one was public for just 21 days before CISA confirmed exploitation — faster than Citrix’s 120-day median, meaning attackers moved unusually quickly.
| Citrix in the CISA KEV catalog | Value |
|---|---|
| Tracked KEV entries | 24 |
| Median lag (public → KEV listing) | 120 days |
| 0-day rate (exploited at or before disclosure) | 21% |
| Entries tied to known ransomware campaigns | 7 |
For perspective, the median across all 1709 tracked KEV entries is 252 days — Citrix’s exploited vulnerabilities are flagged faster than the catalog average.
Other Recent Citrix KEV Additions
The most recent Citrix vulnerabilities CISA has confirmed as actively exploited, from our tracker:
| CVE | Product | Added to KEV | Lag (days) | Ransomware |
|---|---|---|---|---|
| CVE-2026-8452 | NetScaler ADC and NetScaler Gateway | August 26, 2026 | 57 | No |
| CVE-2026-3055 | NetScaler | March 30, 2026 | 7 | No |
| CVE-2025-7775 | NetScaler | August 26, 2025 | 0 | No |
| CVE-2024-8069 | Session Recording | August 25, 2025 | 286 | No |
| CVE-2024-8068 | Session Recording | August 25, 2025 | 286 | No |
What This Means for Defenders
CISA has added CVE-2026-19490, an authentication bypass vulnerability in Citrix NetScaler, to its Known Exploited Vulnerabilities (KEV) catalog. It has a critical CVSS base score of 9.8. Federal agencies must patch by September 12, 2026, just three days after its KEV listing. All organizations using Citrix NetScaler appliances, especially those exposed to the internet, are at high risk and should prioritize this update.
This vulnerability was public for 21 days before its KEV listing, indicating rapid exploitation. Although ransomware use isn’t confirmed for this CVE, the quick KEV addition signals active, widespread exploitation. Organizations that can’t patch immediately should restrict access to affected NetScaler instances, enforce strict network segmentation, and implement multi-factor authentication for all administrative interfaces. Continuous monitoring for unusual activity is also important.
Related Coverage
- Citrix’s CVE-2026-8452 Was Exploited in 57 Days — Faster Than Its 183-Day Median (August 2026)
- Critical Microsoft SharePoint Flaw CVE-2026-50522 (CVSS 9.8) Added to CISA KEV (July 2026)
How We Track This
This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.