Exploited Vulnerabilities Daily
🌐 English

← All new entries

CVE-2026-19490: Citrix NetScaler

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.

Vendor
Citrix
Product
NetScaler
Vulnerability
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Date added
Sep 9, 2026
CISA due date (U.S. federal agencies)
Sep 12, 2026
Known ransomware campaign use
Unknown
Weakness (CWE)
CWE-288

References

This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.

Last updated: · Catalog version 2026.10.02