← back

CVE-2026-19490

KEV EPSS 5.6%
hype MIXED · 38 hack

Real vulnerability, vendor patching, but no KEV-listing, unconfirmed CVSS, zero EPSS signal.

What: Authentication bypass in Citrix NetScaler ADC and Gateway (versions 13.1–63.21, 14.1–73.32) enabling unauthenticated remote access to VPN and AAA deployments.

Why it matters: Published 2026-08-19; social chatter cites critical severity and urgent patching calls from Citrix. However, CVSS is unlisted (posts claim 9.3), EPSS is extremely low (0.27736 percentile), and CVE is not KEV-listed. No public PoC or in-the-wild exploitation confirmed in posts. Vendor advisory referenced but no confirmed active defense activity yet.

Where it's seen: Bluesky posts amplifying Citrix vendor advisory; security news aggregation; no defender triage or PoC repositories mentioned.

RISK: HIGH — Unauthenticated auth bypass on edge appliance; urgent patching signaled despite low EPSS.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 8/21/2026, 1:23:12 PM

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.