CISA Warns of Active Attacks on Critical NetScaler Flaw
Federal agencies have three days to patch CVE-2026-19490 after CISA confirmed criminals are actively exploiting the high-severity flaw in Citrix's widely used network gateway software.

Key points
- CISA added CVE-2026-19490, a flaw scoring 9.3 out of 10 on the standard severity scale, to its official list of known exploited vulnerabilities on Wednesday.
- Citrix patched the vulnerability on August 19, 2026; active exploitation appears to have begun September 3, one day after a working attack method was published publicly on GitHub.
- All NetScaler ADC and NetScaler Gateway appliances configured as a gateway or authentication server are affected.
- Federal agencies must apply the patch within three days, under binding rules set out in BOD 26-04 (Binding Operational Directive 26-04, a mandatory security instruction issued to U.S. government departments).
- Cybersecurity firm Rapid7 flagged the flaw at patch release, warning that NetScaler appliances are high-value targets that criminals move against quickly.
What is this flaw and who is at risk?
CVE-2026-19490 is a critical security flaw in two Citrix products: NetScaler ADC (Application Delivery Controller, software that manages how web traffic flows into a company's network) and NetScaler Gateway (a remote-access tool that lets employees log in securely from outside the office). Both are used heavily by large organisations.
The flaw allows a criminal to attack the system from the internet without needing a username or password. That makes it especially dangerous: most attacks require stealing credentials first. Here, none are needed.
Every appliance configured as a gateway, including SSL VPN (a type of encrypted remote-access tunnel), or as an authentication server, is vulnerable. That covers a large share of enterprise NetScaler deployments worldwide.
How did we get here?
Citrix issued a patch on August 19. The same day, security firm Rapid7 published an analysis warning the flaw would be attractive to criminals, given how many organisations rely on NetScaler for remote access.
The prediction was accurate. On September 2, a proof-of-concept exploit (a working demonstration of how to abuse the flaw) appeared on GitHub, the public code-sharing platform. By September 3, exploitation was underway.
Ryan Dewhurst, founder of threat-intelligence firm Previdian, observed scanning traffic almost immediately. "An unverified but credible PoC appeared yesterday. Today, 3 IPs across 3 countries sent matching requests to our sensor," he wrote. Previdian's data places the start of exploitation on September 3, and CISA's public warning came roughly a week later.
| Event | Date |
|---|---|
| Citrix patch released | August 19, 2026 |
| Rapid7 advisory published | August 19, 2026 |
| Public exploit posted to GitHub | September 2, 2026 |
| First confirmed exploitation observed | September 3, 2026 |
| CISA adds to Known Exploited Vulnerabilities list | September (Wednesday) 2026 |
| Federal agency patch deadline (BOD 26-04) | Three days from CISA listing |
Should employees and customers be worried?
If your employer uses Citrix NetScaler to let staff work remotely, it is worth asking your IT team whether the August 19 patch has been applied. A successful attack on an unpatched gateway can give criminals a foothold inside a corporate network, which may lead to data theft or, in worse cases, ransomware (malicious software that locks company files until a ransom is paid).
Ordinary users cannot patch this themselves. The action sits entirely with IT and security teams. What staff can do is stay alert to unusual account activity or unexpected password-reset requests, which can be early signs that a network has been breached.
Rapid7's advice, reported by SecurityWeek, was direct: treat patching as an emergency, not routine maintenance.
Common questions
Do non-government organisations have to comply with the three-day deadline?
No. The BOD 26-04 directive legally binds U.S. federal civilian agencies only. Private companies and state governments face no mandatory deadline under this specific rule, though regulators such as the SEC (Securities and Exchange Commission) expect publicly listed companies to manage known vulnerabilities promptly under separate disclosure obligations.
What should IT teams do right now?
Apply the Citrix patch released on August 19. Organisations that cannot patch immediately should consider taking affected gateway appliances offline or restricting access to them until the update is applied.



