{"id":1587,"date":"2026-09-14T11:03:15","date_gmt":"2026-09-14T05:33:15","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1587"},"modified":"2026-09-17T10:09:52","modified_gmt":"2026-09-17T04:39:52","slug":"cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/","title":{"rendered":"CVE-2026-19490: Citrix NetScaler Flaw Joins CISA KEV List"},"content":{"rendered":"<p>CISA has added CVE-2026-19490, an authentication bypass in Citrix NetScaler ADC and Gateway, to its Known Exploited Vulnerabilities catalog. The agency listed it alongside CVE-2026-20079 and CVE-2025-25249. Federal civilian agencies had until September 12, 2026, to patch all three.<\/p>\n<p>The grouping isn&#8217;t coincidental. NetScaler, Cisco&#8217;s Secure Firewall Management Center, and Fortinet&#8217;s FortiOS all sit at the network edge, where they broker <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-virtual-private-network-vpn\/\">VPN<\/a> sessions, manage firewall fleets, or terminate remote access. Compromise at that layer can undermine authentication, segmentation, and visibility across an entire environment before an endpoint agent ever sees a sign of trouble.<\/p>\n<p>All three have evidence of exploitation or exploit attempts in the wild. Honeypot telemetry, vendor advisories, and independent threat research each show active attacker interest, with the NetScaler flaw drawing fresh scanning activity in the days before the <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-are-known-exploited-vulnerabilities-kev\/\">KEV<\/a> deadline.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tBook a free demo and explore Hexnode today!<\/a>\r\n    \t\t<\/center><\/p>\n<h2>Three vulnerabilities, one deadline<\/h2>\n<p>Each flaw follows a different path to the same outcome: an attacker who never needed valid credentials ends up with control of a system other defenses depend on.<\/p>\n    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle  \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Note:<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tThis section covers the three flaws CISA added to the KEV catalog on September 9, 2026, under the shared September 12 deadline. A separate Cisco FMC flaw, CVE-2026-20316 (hard-coded credentials), was added to KEV in July 2026 under its own deadline and sits outside this piece&#8217;s scope, though some attackers have chained it with CVE-2026-20079.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<ul>\n<li><strong>CVE-2026-19490 (Citrix NetScaler ADC\/Gateway):<\/strong> It affects Gateway or AAA virtual-server configurations, subject to version-specific SAML-action requirements. The bypass lets an attacker skip the login process entirely on these configurations.<\/li>\n<li><strong>CVE-2026-20079 (Cisco Secure FMC):<\/strong> Stems from an improperly created system process at boot time. An unauthenticated attacker can send crafted HTTP requests to execute scripts and gain root access. Its 10.0<a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-common-vulnerability-scoring-system-cvss\/\"> CVSS<\/a> score reflects remote, unauthenticated exploitation, low complexity, scope change, and high confidentiality, integrity, and availability impacts.<\/li>\n<li><strong>CVE-2025-25249 (FortiOS\/FortiSwitchManager\/FortiSASE):<\/strong> A heap-based buffer overflow. It carries a 9.8 CVSS score. A remote, unauthenticated attacker can trigger it with specifically crafted requests to execute arbitrary code or commands.<\/li>\n<\/ul>\n<h3>Vulnerability comparison at a glance<\/h3>\n<table style=\"width: 97.0661%;\">\n<thead>\n<tr>\n<th style=\"width: 33.7691%; text-align: left;\"><strong>Vulnerability<\/strong><\/th>\n<th style=\"width: 17.8649%; text-align: left;\"><strong>CVSS<\/strong><\/th>\n<th style=\"width: 47.1678%; text-align: left;\"><strong>Operational Risk<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 33.7691%;\">CVE-2026-19490 (Citrix NetScaler ADC\/Gateway)<\/td>\n<td style=\"width: 17.8649%;\">9.3<\/td>\n<td style=\"width: 47.1678%;\">Undermines remote-access trust; already drawing active scanning<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.7691%;\">CVE-2026-20079 (Cisco Secure FMC)<\/td>\n<td style=\"width: 17.8649%;\">10.0<\/td>\n<td style=\"width: 47.1678%;\">Exposes the firewall management plane and stored configuration data<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.7691%;\">CVE-2025-25249 (Fortinet products)<\/td>\n<td style=\"width: 17.8649%;\">9.8<\/td>\n<td style=\"width: 47.1678%;\">Enables persistent, hands-on-keyboard access via PivotC2<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Exploitation already underway<\/h2>\n<p>CISA&#8217;s KEV listing followed confirmed attacker activity, not just theoretical risk. CISA, Cisco, and independent researchers reported exploitation or exploit attempts before the September 12 deadline.<\/p>\n<ul>\n<li><strong>NetScaler:<\/strong> A Previdian sensor detected exploit-matching requests from three source IPs on September 3, 2026.<\/li>\n<li><strong>Cisco FMC:<\/strong> Cisco updated its advisory to confirm it became aware of active exploitation in August 2026. Talos identified three FMC intrusion clusters using different methods, including web shells, reverse shells, implants, tunneling tools, and ransomware.<\/li>\n<li><strong>Fortinet:<\/strong> SOCRadar reported a campaign that weaponized CVE-2025-25249 to deliver PivotC2, a Node.js remote access <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-trojan\/\">trojan<\/a> with interactive shells, tunneling, network scanning, and FortiGate-specific configuration harvesting. More than 30,000 IP addresses were targeted, resulting in 178 confirmed PivotC2 infections, mostly in the U.S.The activity is assessed, not confirmed, as the work of a Russian-speaking, financially motivated threat actor. The earliest observed exploitation dates back to July 2026.<\/li>\n<\/ul>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-challenges.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Top 10 Cybersecurity Challenges for Enterprises<\/h4><p>Tackle your enterprise's top ten cybersecurity challenges before attackers do.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/top-10-cybersecurity-challenges-for-enterprises\/\" aria-label=\"Top 10 Cybersecurity Challenges for Enterprises\"><\/a><\/div><\/div><\/div>\n<h2>Why network edge exploitation keeps working<\/h2>\n<p>These three <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-vulnerability-in-cybersecurity\/\">vulnerabilities<\/a> aren&#8217;t isolated missteps. They reflect structural weaknesses that make network-edge devices a recurring target.<\/p>\n<ul>\n<li>These devices often sit directly on the internet perimeter, reducing the number of steps between <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-initial-access-in-cybersecurity\/\">initial access<\/a> and a foothold.<\/li>\n<li>Compromising a VPN gateway or firewall manager can bypass authentication controls that endpoint and identity tools assume are already enforced upstream.<\/li>\n<li>Edge appliances frequently lack the same telemetry retention as workstations or servers, making post-exploitation activity harder to reconstruct after the fact.<\/li>\n<li>A compromised FMC management plane can expose configurations and support attacks against connected environments.<\/li>\n<\/ul>\n<h2>Where Hexnode fits<\/h2>\n<p>Hexnode does not patch NetScaler, FMC, or FortiOS, and it does not monitor logs from those third-party appliances directly. Vendor remediation and network-level controls remain the responsibility of Citrix, Cisco, and Fortinet.<\/p>\n<ul>\n<li><strong>Patch governance:<\/strong> <a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> supports patch and configuration management across Windows, macOS, and Linux endpoints, keeping client-side software current while edge-device remediation is underway.<\/li>\n<li><strong>Threat hunting:<\/strong> On managed Windows and macOS endpoints, <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> can investigate suspicious activity, supporting the search for signs that a network-edge compromise reached a workstation.<\/li>\n<li><strong>Access gating:<\/strong> Through its Conditional Access integration with Microsoft Entra ID, compliance data currently reports for Android, iOS, and macOS devices, which can help restrict resource access on those platforms while an edge incident is under investigation.<\/li>\n<\/ul>\n<p>These capabilities complement, rather than replace, the vendor patches, credential rotation, and application-specific forensics that each vulnerability requires.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-xdr-infosheet.png?format=webp\" class=\"resource-box__image\" alt=\"hexnode xdr infosheet\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-xdr-infosheet.png?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-xdr-infosheet-300x225.png?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-xdr-infosheet-768x576.png?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-xdr-infosheet-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"hexnode xdr infosheet\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Hexnode XDR Info Sheet\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Hexnode XDR unifies detection, investigation, and automated response with UEM for continuous enterprise threat visibility.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/hexnode-xdr-info-sheet\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Patch and containment priorities<\/h2>\n<p>Patching the exposed appliance is the first step, not the last one.<\/p>\n<ul>\n<li>Patch the vulnerable NetScaler, FMC, or FortiOS instance first.<\/li>\n<li>Keep admin workstation patching current, separately. This reduces a different attack surface and doesn&#8217;t remediate the appliance-side vulnerability itself.<\/li>\n<li>Rotate credentials and session secrets that may have transited a compromised gateway. Patching may not invalidate sessions or credentials exposed before remediation.<\/li>\n<\/ul>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does patching CVE-2026-19490 or CVE-2026-20079 remove any access an attacker may have already gained?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. Patching closes the vulnerability but does not undo prior compromise. Organizations should review logs and rotate credentials separately.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Do organizations without on-premises Cisco FMC or Fortinet gear still need to act on this KEV update?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Yes, if any NetScaler, FMC, or Fortinet product is in use. Each vulnerability affects a specific product line independently, so exposure depends on which systems are deployed.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What makes CVE-2026-20079 score a maximum 10.0 while CVE-2026-19490 scores 9.3?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>CVE-2026-20079&#8217;s CVSS vector includes a scope change, since compromising the FMC console can extend to devices it manages, an added factor CVE-2026-19490 doesn&#8217;t carry.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>Three unrelated vendors, one shared lesson: network-edge appliances remain a preferred entry point precisely because they sit outside the visibility most security teams have built around endpoints and identity. These vulnerabilities show how authentication bypass and memory-corruption flaws at the perimeter can undermine other security controls.<\/p>\n<p>Patch exposed appliances immediately, validate configurations against documented <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-attack-path\/\">attack paths<\/a>, and rotate potentially exposed secrets. Then correlate any downstream endpoint activity against the exposure window these vulnerabilities created.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stay ahead of the next KEV update.<\/h5><p>Get exploited-vulnerability alerts and remediation guidance direct to your inbox. <\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>CISA has added CVE-2026-19490, an authentication bypass in Citrix NetScaler ADC and Gateway, to its&#8230;<\/p>\n","protected":false},"author":5,"featured_media":1643,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,20],"class_list":["post-1587","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-network-and-vpn","product_category-extended-detection-and-response","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CVE-2026-19490: Citrix NetScaler Flaw Joins CISA KEV Deadline<\/title>\n<meta name=\"description\" content=\"CISA added CVE-2026-19490, a Citrix NetScaler auth bypass, to its KEV catalog with a Sept 12 patch deadline.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CVE-2026-19490: Citrix NetScaler Flaw Joins CISA KEV Deadline\" \/>\n<meta property=\"og:description\" content=\"CISA added CVE-2026-19490, a Citrix NetScaler auth bypass, to its KEV catalog with a Sept 12 patch deadline.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-14T05:33:15+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-17T04:39:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cve-2026-19490.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"CVE-2026-19490: Citrix NetScaler Flaw Joins CISA KEV List\",\"datePublished\":\"2026-09-14T05:33:15+00:00\",\"dateModified\":\"2026-09-17T04:39:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\\\/\"},\"wordCount\":1122,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cve-2026-19490.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Network and VPN\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\\\/\",\"name\":\"CVE-2026-19490: Citrix NetScaler Flaw Joins CISA KEV Deadline\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cve-2026-19490.jpeg?format=webp\",\"datePublished\":\"2026-09-14T05:33:15+00:00\",\"dateModified\":\"2026-09-17T04:39:52+00:00\",\"description\":\"CISA added CVE-2026-19490, a Citrix NetScaler auth bypass, to its KEV catalog with a Sept 12 patch deadline.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cve-2026-19490.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cve-2026-19490.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"cve 2026 19490\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CVE-2026-19490: Citrix NetScaler Flaw Joins CISA KEV List\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"description\":\"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CVE-2026-19490: Citrix NetScaler Flaw Joins CISA KEV Deadline","description":"CISA added CVE-2026-19490, a Citrix NetScaler auth bypass, to its KEV catalog with a Sept 12 patch deadline.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/","og_locale":"en_US","og_type":"article","og_title":"CVE-2026-19490: Citrix NetScaler Flaw Joins CISA KEV Deadline","og_description":"CISA added CVE-2026-19490, a Citrix NetScaler auth bypass, to its KEV catalog with a Sept 12 patch deadline.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-14T05:33:15+00:00","article_modified_time":"2026-09-17T04:39:52+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cve-2026-19490.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"CVE-2026-19490: Citrix NetScaler Flaw Joins CISA KEV List","datePublished":"2026-09-14T05:33:15+00:00","dateModified":"2026-09-17T04:39:52+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/"},"wordCount":1122,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cve-2026-19490.jpeg?format=webp","articleSection":["Identity Abuse","Network and VPN"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/","url":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/","name":"CVE-2026-19490: Citrix NetScaler Flaw Joins CISA KEV Deadline","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cve-2026-19490.jpeg?format=webp","datePublished":"2026-09-14T05:33:15+00:00","dateModified":"2026-09-17T04:39:52+00:00","description":"CISA added CVE-2026-19490, a Citrix NetScaler auth bypass, to its KEV catalog with a Sept 12 patch deadline.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cve-2026-19490.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cve-2026-19490.jpeg?format=webp","width":1340,"height":700,"caption":"cve 2026 19490"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-19490-citrix-netscaler-flaw-joins-cisa-kev-list\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"CVE-2026-19490: Citrix NetScaler Flaw Joins CISA KEV List"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"description":"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1587","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1587"}],"version-history":[{"count":6,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1587\/revisions"}],"predecessor-version":[{"id":1715,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1587\/revisions\/1715"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1643"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1587"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1587"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}