ZeroHour
Story · 2 sources · 3 articlesfirst updated ()

Exploited Citrix NetScaler auth bypass CVE-2026-19490 lands on CISA KEV with September 12 federal patch deadline

What's new: Since the previous summary (2026-09-09): (1) New reporting on 2026-09-10 completes the cut-off KEV item — the listing carries a 12 September 2026 deadline for FCEB agencies under BOD 26-04, three days from the 9 September addition. (2) Exploitation details emerged: Previdian telemetry shows attacks since at least 3 September 2026, one day after a public exploit appeared on GitHub, with 56…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

CISA added actively exploited Citrix NetScaler authentication bypass CVE-2026-19490 (CVSS 9.3) to the Known Exploited Vulnerabilities catalog on 9 September 2026, ordering federal civilian agencies to patch by 12 September under BOD 26-04; honeypots logged 56…

Citrix published a security advisory on 19 August 2026 fixing two critical-severity issues in NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, plus FIPS/NDcPP builds; fixed builds are 14.1-73.32, 13.1-63.21, and FIPS build 13.1-37.277 (the Canadian Centre also lists 14.1-73.32 for FIPS variants). CVE-2026-19490 (CVSS 9.3, CWE-288) is an authentication bypass via an alternate path exploitable by a remote unauthenticated attacker when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server; Rapid7 assessed it is remotely exploitable without authentication. Sources agree a SAML-related configuration is involved but differ on specifics: CERT-EU says a SAML action configuration is a precondition on builds 14.1-43.56+ and 13.1-61.28+, the Canadian Centre for Cyber Security and Cyber Security News describe appliances configured as a SAML IdP, and Security Affairs characterizes it as a SAML HTTP-Redirect binding authentication bypass. CVE-2026-19489 (CVSS 8.8, CWE-120) is a classic buffer overflow causing memory overflow, unpredictable behaviour, or denial-of-service conditions; the sources disagree on the vulnerable configuration — CERT-EU says it requires SIP ALG enabled on a Large Scale NAT (LSN) group, whereas the Canadian Centre ties it to a SAML IdP configuration. The Canadian Centre issued alert AL26-019 on 2026-09-04 and updated it as AV26-833 Update 1 on 2026-09-09, the same day CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog. Reports on 2026-09-10 (SecurityWeek, The Hacker News, Cyber Security News, Security Affairs) specify that the KEV entry gives Federal Civilian Executive Branch agencies until 12 September 2026 to patch under BOD 26-04 — three days from the listing — with Cyber Security News noting mandatory forensic triage. Previdian sensor data shows exploitation ongoing since at least 3 September 2026, one day after a public exploit appeared on GitHub; honeypots recorded 56 attack attempts between 3 and 8 September, with matching requests from three IP addresses across three countries. Cyber Security News reported no confirmed production compromises as of 10 September, while CISA's KEV listing itself indicates confirmed active exploitation. The Canadian Centre urges emergency patching and monitoring of authentication logs for unauthorized access. The same September KEV batch also added Cisco Secure Firewall Management…

  • CVE-2026-19490 (CVSS 9.3, CWE-288): remote unauthenticated authentication bypass via alternate path on NetScaler ADC/Gateway configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server; Rapid7 says it is remotely…
  • CVE-2026-19489 (CVSS 8.8, CWE-120): buffer overflow causing memory overflow, unpredictable behaviour, or denial of service; CERT-EU says it requires SIP ALG on an LSN group while the Canadian Centre ties it to a SAML IdP configuration…
  • Affected: NetScaler ADC/Gateway 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, plus FIPS/NDcPP builds; fixed in 14.1-73.32, 13.1-63.21, and FIPS build 13.1-37.277.
  • Citrix published the advisory on 19 August 2026; Canadian Centre alert AL26-019 followed on 2026-09-04 and was updated as AV26-833 Update 1 on 2026-09-09.
  • CISA added CVE-2026-19490 to the KEV catalog on 9 September 2026; Federal Civilian Executive Branch agencies must patch by 12 September 2026 under BOD 26-04 (three days), with mandatory forensic triage per Cyber Security News.
  • Previdian sensor data shows exploitation since at least 3 September 2026, one day after a public exploit appeared on GitHub; 56 honeypot attack attempts were recorded 3-8 September from three IPs across three countries; no confirmed…
  • Sources disagree on the CVE-2026-19490 SAML precondition: CERT-EU cites a SAML action condition on builds 14.1-43.56+/13.1-61.28+, the Canadian Centre and Cyber Security News describe SAML IdP configuration, Security Affairs describes a…
  • Same KEV batch also included Cisco FMC CVE-2026-20079 (CVSS 10.0, exploited since August 2026), Chrome V8 CVE-2026-87491 (CVSS 8.8, fixed in Chrome 153.0.8010.36, seventh exploited Chrome zero-day of 2026), and FortiOS CVE-2025-25249…

Coverage timeline

  1. · Mar 23, 2026
    CERT-EU Advisories· 55
    2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC

    Citrix NetScaler ADC and Gateway flaws enable memory information disclosure and user session mix-up; no active exploitation is observed yet.

  2. · 27d ago
    CERT-EU Advisories· 66
    2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway

    Citrix patched NetScaler ADC/Gateway: auth bypass CVE-2026-19490 (CVSS 9.3) on Gateway/AAA configs and memory overflow CVE-2026-19489 (CVSS 8.8) requiring SIP ALG.

  3. · 11d ago
    Canadian Centre for Cyber Security· 68
    AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489

    Canadian Cyber Centre alerts on Citrix NetScaler ADC/Gateway flaws CVE-2026-19490 (authentication bypass) and CVE-2026-19489 (buffer overflow), urging emergency patching.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-25249
Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE

CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known.

Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product.

9.82% KEV PoC
  • Fortinet FortiOS
  • Fortinet FortiSwitchManager
  • Fortinet FortiSASE
mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants)
CVE-2026-19489
Unauthenticated Buffer Overflow in Citrix NetScaler ADC and NetScaler Gateway

CVE-2026-19489 is a vulnerability in Citrix NetScaler ADC and NetScaler Gateway classified as a classic buffer overflow (CWE-120), meaning input is copied into a buffer without adequate size checks; it was disclosed by Citrix alongside CVE-2026-19490, the authentication bypass receiving most of the headline attention. Per the CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N), the flaw is reachable over the network by an unauthenticated remote attacker with no user interaction, though detailed trigger conditions are not spelled out in the CVE description. The scoring (VC:L/VI:L/VA:H, base 8.8 High) indicates the primary impact is to availability — likely crashes or denial of service on the appliance — with low confidentiality and integrity impact. All organizations running NetScaler ADC or NetScaler Gateway 14.1 releases through build 73.32, or 13.1 releases through build 63.21, fall within the affected ranges. There is no evidence of exploitation so far: the issue is not in CISA KEV, has no known public proof-of-concept, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days (32nd percentile).

Do: Upgrade affected NetScaler ADC and NetScaler Gateway deployments to the fixed builds identified in Citrix's advisory (see AL26-019 and CISA advisory AV26-833 Update 1); affected ranges are 14.1 through build 73.32 and 13.1 through build 63.21. Until patched, limit internet exposure of appliance interfaces and monitor Citrix channels for signs of exploitation. Also verify whether the same appliances are affected by the related CVE-2026-19490 authentication bypass fixed in the same advisory.

8.8<1%
  • Citrix NetScaler ADC (formerly Citrix ADC) 14.1 releases through build 73.32; 13.1 releases through build 63.21
  • Citrix NetScaler Gateway (formerly Citrix Gateway) 14.1 releases through build 73.32; 13.1 releases through build 63.21
mass≈100,000+ internet-exposed NetScaler ADC/Gateway appliances (order-of-magnitude estimate; not all run affected builds)
CVE-2026-19490
Remote Authentication Bypass in Citrix NetScaler ADC and NetScaler Gateway

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability (CWE-288, 'using an alternate path or channel') that an unauthenticated remote threat actor can exploit. The flaw is triggerable when the appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy deployments, allowing the attacker to bypass authentication without valid credentials. A successful bypass could give an attacker access to VPN-protected or AAA-gated resources as an authenticated user; no CVSS score has been published yet. Organizations running affected NetScaler appliances in these configurations are exposed, and affected version ranges are not specified in the available data, so defenders should consult Citrix advisory AL26-019. The flaw was added to CISA's KEV on 2026-09-09, indicating exploitation in the wild; ransomware use is unknown, no public PoC is known, and EPSS assigns a 3.4% probability of exploitation within 30 days (88th percentile).

Do: Prioritize applying vendor fixes or mitigations per Citrix advisory AL26-019 in line with CISA BOD 26-04, focusing first on internet-facing appliances configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy). Until patched, restrict internet exposure and review VPN/AAA authentication logs for signs of unauthenticated access, following CISA's Forensics Triage Requirements if compromise is suspected.

9.36% KEV PoC
  • Citrix NetScaler ADC and NetScaler Gateway
largeon the order of 10,000-100,000 internet-exposed NetScaler ADC/Gateway appliances
CVE-2026-20079
Authentication bypass to root access in Cisco Secure Firewall Management Center

CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.

Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected.

10.076% KEV PoC ×2
  • Cisco Secure Firewall Management Center (FMC) Software (web interface)
  • Cisco Security Cloud Control (SCC) Firewall Management
largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands)
CVE-2026-3055
Out-of-Bounds Read in Citrix NetScaler ADC and Gateway When Used as SAML IDP

CVE-2026-3055 is an out-of-bounds read (CWE-125) in Citrix NetScaler ADC and NetScaler Gateway caused by insufficient input validation when the appliance is configured as a SAML Identity Provider (IDP). An unauthenticated remote attacker can trigger the flaw by sending crafted input to the SAML IDP functionality, causing the appliance to read beyond the bounds of allocated memory and potentially disclose sensitive information from it. The CVSS 4.0 base score of 9.3 (critical) reflects a network-vector flaw requiring no privileges or user interaction. Only organizations running NetScaler ADC or NetScaler Gateway appliances with SAML IDP configured are affected, according to the available data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-30, carries an 87.2% EPSS probability of exploitation within 30 days, has a public proof-of-concept, and headlines indicate active reconnaissance and exploitation against NetScaler deployments, including federal patch directives.

Do: Apply the patched NetScaler ADC and NetScaler Gateway releases from Citrix's advisory as soon as possible, prioritizing internet-facing appliances (exact fixed version numbers are not in this data; check the vendor bulletin). Determine whether SAML IDP is configured on your appliances and, if it is not needed, disable or unbind it as an interim mitigation while reviewing appliance logs for suspicious authentication or reconnaissance traffic. Federal agencies must follow the CISA required action and BOD 22-01 guidance, with CISA directing patching by the stated Thursday deadline.

9.387% KEV PoC
  • Citrix NetScaler ADC
  • Citrix NetScaler Gateway
largetens of thousands of internet-exposed NetScaler ADC/Gateway appliances, with the directly exposed subset limited to those configured as SAML IDPs
CVE-2026-4368
Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leadin

Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup

NVD description · AI analysis pending
7.74%
CVE-2026-87491
Actively Exploited Out-of-Bounds Write in Google Chrome V8

CVE-2026-87491 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine in Google Chrome, fixed in Chrome 153.0.8010.36, which Google shipped alongside roughly 230 other security fixes. An attacker can trigger the flaw remotely by luring a user (user interaction required) into opening a crafted HTML page that corrupts memory in V8. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome browser sandbox, which constrains but does not eliminate the impact. All Google Chrome users running versions prior to 153.0.8010.36 are affected; because the flaw resides in V8, CISA tracks it as 'Google Chromium V8', and other Chromium-based browsers may inherit the fix in their own updates. The flaw is being actively exploited in the wild — it is the seventh actively exploited Chrome zero-day of 2026 and was added to CISA's KEV catalog on 2026-09-09 — though no public proof-of-concept is known and ransomware use is unknown.

Do: Update Google Chrome to 153.0.8010.36 or later immediately (open Help > About Google Chrome to force the update and relaunch), and verify the version on all endpoints. Also patch headless or automated Chrome deployments (CI runners, scrapers, kiosks, CDP-based tooling) that may lag auto-updates, and prioritize remediation per CISA KEV and BOD 26-04 requirements for federal systems. No public PoC is known and ransomware use is unknown, but confirmed in-the-wild exploitation warrants urgent patching.

8.8<1% KEV
  • Google Chrome (V8 JavaScript engine; tracked by CISA as 'Google Chromium V8') prior to 153.0.8010.36
massbillions of installations (Chrome's install base exceeds 3 billion users)