CISA Directs Federal Agencies to Patch Critical NetScaler Vulnerability
CISA has added a critical authentication bypass vulnerability in Citrix NetScaler to its Known Exploited Vulnerabilities catalog, mandating a September 12th patching deadline for federal agencies.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical vulnerability affecting Citrix NetScaler appliances to its catalog of Known Exploited Vulnerabilities. This directive mandates that Federal Civilian Executive Branch agencies must apply necessary patches by September 12, 2026. The vulnerability, designated CVE-2026-19490, is described as an authentication bypass flaw with a high CVSS score of 9.3 when the NetScaler ADC and NetScaler Gateway are configured as an AAA virtual server or Gateway.
Exploitation of this critical flaw has been observed in the wild, with threat actors actively targeting vulnerable NetScaler systems. According to data from Previdian’s honeypot systems, at least 56 exploitation attempts were registered since September 3, 2026, with a significant surge of 36 attempts occurring on September 8 alone. This activity underscores the urgent need for federal agencies to address the vulnerability promptly. The exploitation efforts appear to be coordinated, with data indicating attempts originating from 3 IP addresses across 3 different countries.
Citrix released a patch for CVE-2026-19490 on August 19, 2026, shortly before widespread exploitation was detected. The exploitation campaign appears to have gained momentum on or after September 3, 2026, which was reportedly one day after a proof-of-concept exploit was made publicly available on GitHub. The ongoing exploitation highlights the rapid weaponization of newly disclosed vulnerabilities by malicious actors.
CISA’s inclusion of CVE-2026-19490 in its KEV catalog means that agencies must now implement the provided mitigations or workarounds to protect their networks. Failure to comply with the mandated September 12 deadline could expose federal systems to significant security risks, potentially leading to unauthorized access and data breaches.
The vulnerability specifically impacts NetScaler Application Delivery Controller (ADC) and NetScaler Gateway appliances when they are operating in specific configurations, namely as a gateway or an AAA (Authentication, Authorization, and Accounting) virtual server. This particular configuration is common for managing user access and security policies, making its compromise a high-priority concern for organizations relying on these services.
This action by CISA is part of a broader effort to secure federal networks against known cyber threats. The agency regularly updates its KEV catalog with vulnerabilities that pose a significant risk to government systems and critical infrastructure, providing clear directives and deadlines for remediation. The inclusion of this Citrix NetScaler authentication bypass vulnerability emphasizes the critical nature of patching promptly once vendor fixes become available and exploitation is confirmed.
The cybersecurity landscape continues to evolve rapidly, with new vulnerabilities being discovered and exploited regularly. This incident serves as a stark reminder of the persistent threat posed by sophisticated actors and the importance of robust vulnerability management programs within federal agencies and beyond. By mandating timely patching, CISA aims to reduce the attack surface and prevent potential cyber incidents.