CVE-2026-19490
KEV EPSS 5.6%Real vulnerability, vendor patching, but no KEV-listing, unconfirmed CVSS, zero EPSS signal.
What: Authentication bypass in Citrix NetScaler ADC and Gateway (versions 13.1–63.21, 14.1–73.32) enabling unauthenticated remote access to VPN and AAA deployments.
Why it matters: Published 2026-08-19; social chatter cites critical severity and urgent patching calls from Citrix. However, CVSS is unlisted (posts claim 9.3), EPSS is extremely low (0.27736 percentile), and CVE is not KEV-listed. No public PoC or in-the-wild exploitation confirmed in posts. Vendor advisory referenced but no confirmed active defense activity yet.
Where it's seen: Bluesky posts amplifying Citrix vendor advisory; security news aggregation; no defender triage or PoC repositories mentioned.
RISK: HIGH — Unauthenticated auth bypass on edge appliance; urgent patching signaled despite low EPSS.
Description
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.