CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog on September 9, 2026, including a critical Citrix NetScaler authentication-bypass flaw, CVE-2026-19490, and a Fortinet heap-based buffer overflow, CVE-2025-25249. Both vendors make network edge appliances — VPN gateways and application delivery controllers — that sit directly on the internet perimeter of thousands of organizations.
Citrix disclosed CVE-2026-19490 in a security bulletin alongside a related flaw, CVE-2026-19489, describing an authentication bypass using an alternate path or channel in NetScaler ADC and NetScaler Gateway. Rapid7's advisory places the CVSS 4.0 base score at 9.3, in the critical range, and notes the flaw affects ADC and Gateway versions from 14.1 through 73.32 and from 13.1 through 63.21.
Why it matters
NetScaler devices have been a recurring target for ransomware crews and nation-state actors for years because compromising the appliance often grants a foothold deep inside a corporate network, bypassing perimeter defenses entirely. An authentication bypass — as opposed to a bug requiring valid credentials — is especially dangerous because it removes the one barrier that normally stops opportunistic scanning from turning into a breach.
The pairing of a Citrix flaw with a Fortinet flaw in the same KEV batch reflects a broader pattern: edge devices from a handful of vendors account for a disproportionate share of KEV catalog additions in 2026, because they are internet-facing, hard to instrument with endpoint security tools, and frequently run for years without a reboot or update.
How it works
Citrix's own bulletin describes the issue only at a high level as an authentication bypass using an alternate path or channel — a vulnerability class in which an attacker reaches a protected resource through a route that was not subject to the same authentication checks as the primary path. CSIRTS' advisory summary echoes this, describing the flaw as allowing an attacker to bypass authentication controls on the appliance. None of the sources reviewed for this story publish exploit code or step-by-step exploitation details, and this report does not add any.
Evidence
Citrix's security bulletin, CTX696939, is the primary source confirming the vulnerability and listing affected NetScaler ADC and Gateway versions. Rapid7's vulnerability database corroborates the CVSS 9.3 score and affected version ranges, and separately reports the advisory was first published August 19, 2026 and updated September 11. CISA's catalog entry from September 9, 2026 confirms the flaw is being actively exploited and lists it alongside the Fortinet, other unnamed, and additional vulnerabilities in the same batch.
What defenders should do
Organizations running NetScaler ADC or Gateway in the affected version ranges should apply Citrix's patched builds immediately and treat any internet-facing appliance as potentially already compromised if it has been unpatched since the bulletin's August 19 publication. Standard post-compromise steps for edge-device incidents apply: rotate credentials and session tokens that traverse the appliance, review authentication logs for anomalous access patterns predating the patch, and check for unexpected configuration changes or new administrative accounts.
What happens next
Federal civilian agencies face a CISA-mandated deadline to remediate KEV-listed vulnerabilities, and history suggests ransomware operators will move quickly to weaponize public exploitation reporting for NetScaler bugs, as they have with prior Citrix vulnerabilities. Expect further technical writeups from security vendors in the coming weeks as more organizations discover the flaw was exploited before they patched.
