CVE-2026-19490
- CVSS
- —
- EPSS
- —
- CISA KEV
- Added 2026-09-09, due 2026-09-12
- Exploitation
- No report
- Public exploits
- 2 repositories
- State
- Unknown
Coverage
Actively exploitedCISA advisories & alerts
CISA Adds Four Known Exploited Vulnerabilities to Catalog(opens the publisher's site in a new tab)
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or…

Actively exploitedRapid7
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway(opens the publisher's site in a new tab)
Overview On August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated…
What we observed
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- kev addedcisa-kev