Sophia
Hart

CVE-2026-19490: Citrix NetScaler Flaw Joins CISA KEV List

Sophia Hart

Sep 14, 2026

6 min read

cve 2026 19490

TL; DR

  • CISA’s update included four flaws, including CVE-2026-19490, CVE-2026-20079, CVE-2026-20316, and CVE-2025-25249, due September 12.
  • The NetScaler flaw scores 9.3 CVSS and bypasses authentication on AAA and VPN gateways. A Previdian sensor detected exploit-matching requests from three source IPs on September 3.
  • Cisco’s flaw scores 10.0, with Talos linking it to some activity across three FMC intrusion clusters.
  • Fortinet’s flaw has been linked to PivotC2 infections on 178 devices, enabling credential harvesting and internal-network access.

CISA has added CVE-2026-19490, an authentication bypass in Citrix NetScaler ADC and Gateway, to its Known Exploited Vulnerabilities catalog. The agency listed it alongside CVE-2026-20079 and CVE-2025-25249. Federal civilian agencies had until September 12, 2026, to patch all three.

The grouping isn’t coincidental. NetScaler, Cisco’s Secure Firewall Management Center, and Fortinet’s FortiOS all sit at the network edge, where they broker VPN sessions, manage firewall fleets, or terminate remote access. Compromise at that layer can undermine authentication, segmentation, and visibility across an entire environment before an endpoint agent ever sees a sign of trouble.

All three have evidence of exploitation or exploit attempts in the wild. Honeypot telemetry, vendor advisories, and independent threat research each show active attacker interest, with the NetScaler flaw drawing fresh scanning activity in the days before the KEV deadline.

Book a free demo and explore Hexnode today!

Three vulnerabilities, one deadline

Each flaw follows a different path to the same outcome: an attacker who never needed valid credentials ends up with control of a system other defenses depend on.

Note:

This section covers the three flaws CISA added to the KEV catalog on September 9, 2026, under the shared September 12 deadline. A separate Cisco FMC flaw, CVE-2026-20316 (hard-coded credentials), was added to KEV in July 2026 under its own deadline and sits outside this piece’s scope, though some attackers have chained it with CVE-2026-20079.

  • CVE-2026-19490 (Citrix NetScaler ADC/Gateway): It affects Gateway or AAA virtual-server configurations, subject to version-specific SAML-action requirements. The bypass lets an attacker skip the login process entirely on these configurations.
  • CVE-2026-20079 (Cisco Secure FMC): Stems from an improperly created system process at boot time. An unauthenticated attacker can send crafted HTTP requests to execute scripts and gain root access. Its 10.0 CVSS score reflects remote, unauthenticated exploitation, low complexity, scope change, and high confidentiality, integrity, and availability impacts.
  • CVE-2025-25249 (FortiOS/FortiSwitchManager/FortiSASE): A heap-based buffer overflow. It carries a 9.8 CVSS score. A remote, unauthenticated attacker can trigger it with specifically crafted requests to execute arbitrary code or commands.

Vulnerability comparison at a glance

Vulnerability CVSS Operational Risk
CVE-2026-19490 (Citrix NetScaler ADC/Gateway) 9.3 Undermines remote-access trust; already drawing active scanning
CVE-2026-20079 (Cisco Secure FMC) 10.0 Exposes the firewall management plane and stored configuration data
CVE-2025-25249 (Fortinet products) 9.8 Enables persistent, hands-on-keyboard access via PivotC2

Exploitation already underway

CISA’s KEV listing followed confirmed attacker activity, not just theoretical risk. CISA, Cisco, and independent researchers reported exploitation or exploit attempts before the September 12 deadline.

  • NetScaler: A Previdian sensor detected exploit-matching requests from three source IPs on September 3, 2026.
  • Cisco FMC: Cisco updated its advisory to confirm it became aware of active exploitation in August 2026. Talos identified three FMC intrusion clusters using different methods, including web shells, reverse shells, implants, tunneling tools, and ransomware.
  • Fortinet: SOCRadar reported a campaign that weaponized CVE-2025-25249 to deliver PivotC2, a Node.js remote access trojan with interactive shells, tunneling, network scanning, and FortiGate-specific configuration harvesting. More than 30,000 IP addresses were targeted, resulting in 178 confirmed PivotC2 infections, mostly in the U.S.The activity is assessed, not confirmed, as the work of a Russian-speaking, financially motivated threat actor. The earliest observed exploitation dates back to July 2026.

Why network edge exploitation keeps working

These three vulnerabilities aren’t isolated missteps. They reflect structural weaknesses that make network-edge devices a recurring target.

  • These devices often sit directly on the internet perimeter, reducing the number of steps between initial access and a foothold.
  • Compromising a VPN gateway or firewall manager can bypass authentication controls that endpoint and identity tools assume are already enforced upstream.
  • Edge appliances frequently lack the same telemetry retention as workstations or servers, making post-exploitation activity harder to reconstruct after the fact.
  • A compromised FMC management plane can expose configurations and support attacks against connected environments.

Where Hexnode fits

Hexnode does not patch NetScaler, FMC, or FortiOS, and it does not monitor logs from those third-party appliances directly. Vendor remediation and network-level controls remain the responsibility of Citrix, Cisco, and Fortinet.

  • Patch governance: Hexnode UEM supports patch and configuration management across Windows, macOS, and Linux endpoints, keeping client-side software current while edge-device remediation is underway.
  • Threat hunting: On managed Windows and macOS endpoints, Hexnode XDR can investigate suspicious activity, supporting the search for signs that a network-edge compromise reached a workstation.
  • Access gating: Through its Conditional Access integration with Microsoft Entra ID, compliance data currently reports for Android, iOS, and macOS devices, which can help restrict resource access on those platforms while an edge incident is under investigation.

These capabilities complement, rather than replace, the vendor patches, credential rotation, and application-specific forensics that each vulnerability requires.

hexnode xdr infosheet

Hexnode XDR Info Sheet

Hexnode XDR unifies detection, investigation, and automated response with UEM for continuous enterprise threat visibility.

DOWNLOAD

Patch and containment priorities

Patching the exposed appliance is the first step, not the last one.

  • Patch the vulnerable NetScaler, FMC, or FortiOS instance first.
  • Keep admin workstation patching current, separately. This reduces a different attack surface and doesn’t remediate the appliance-side vulnerability itself.
  • Rotate credentials and session secrets that may have transited a compromised gateway. Patching may not invalidate sessions or credentials exposed before remediation.

FAQs

No. Patching closes the vulnerability but does not undo prior compromise. Organizations should review logs and rotate credentials separately.

Yes, if any NetScaler, FMC, or Fortinet product is in use. Each vulnerability affects a specific product line independently, so exposure depends on which systems are deployed.

CVE-2026-20079’s CVSS vector includes a scope change, since compromising the FMC console can extend to devices it manages, an added factor CVE-2026-19490 doesn’t carry.

Conclusion

Three unrelated vendors, one shared lesson: network-edge appliances remain a preferred entry point precisely because they sit outside the visibility most security teams have built around endpoints and identity. These vulnerabilities show how authentication bypass and memory-corruption flaws at the perimeter can undermine other security controls.

Patch exposed appliances immediately, validate configurations against documented attack paths, and rotate potentially exposed secrets. Then correlate any downstream endpoint activity against the exposure window these vulnerabilities created.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.