Last updated: October 5, 2026 at 10:28 AM UTC
All 897 Vulnerability 362 Breach 144 Threat 384 Defense 7
Tag: citrix-netscaler (2 articles)Clear

CISA flags exploited Cisco, Citrix, Fortinet, and WatchGuard edge flaws

CISA added several actively exploited flaws in internet-facing security appliances to its catalog, ordering federal agencies to patch by September 12. The most severe, CVE-2026-20079 scored 10.0, is an authentication bypass in Cisco Secure Firewall Management Center that lets an unauthenticated attacker run scripts and gain root on the device; Cisco confirmed exploitation since August. A Citrix NetScaler authentication bypass, CVE-2026-19490, saw a surge of attacks on September 8, and a Fortinet FortiOS flaw, CVE-2025-25249, is being used to deliver a remote access trojan. Separately, CISA warned that a critical WatchGuard Firebox firewall flaw is now being exploited in ransomware attacks. Edge appliances remain prime targets.

Check
Immediately patch internet-facing Cisco Secure FMC, Citrix NetScaler, Fortinet FortiOS, and WatchGuard Firebox devices to fixed versions, prioritizing anything reachable from the internet, and hunt exposed appliances for signs of compromise.
Affected
Organizations running affected Cisco Secure FMC, Citrix NetScaler, Fortinet FortiOS, or WatchGuard Firebox appliances (CVE-2026-20079, CVE-2026-19490, CVE-2025-25249); all are exploited, from unauthenticated root access to RAT and ransomware deployment.
Fix
Patch these appliances now given the short federal deadline and active exploitation, restrict management interfaces from the internet, monitor for auth-bypass and script-execution activity, and treat any exposed unpatched device as compromised.

Critical Citrix NetScaler flaw lets attackers bypass authentication on gateways

Citrix patched a critical flaw in NetScaler ADC and Gateway that lets a remote, unauthenticated attacker bypass authentication on appliances used for remote access. Tracked as CVE-2026-19490 and scored 9.3, it is an authentication-bypass issue affecting devices configured as a gateway for SSL VPN, ICA proxy, clientless VPN, or RDP proxy, or as an AAA authentication server. On newer builds it requires a SAML configuration, but on older builds any gateway or AAA configuration is exposed. There is no confirmed exploitation yet, but NetScaler appliances sit at the network edge and have repeatedly been attacked soon after disclosure, so patching is urgent.

Check
Upgrade NetScaler ADC and Gateway to the fixed builds immediately, and check your configuration for SAML action, gateway, and AAA virtual server entries to gauge exposure, treating edge appliances as priority targets.
Affected
Organizations running affected Citrix NetScaler ADC or Gateway as a gateway or AAA server (CVE-2026-19490); a remote, unauthenticated attacker can bypass authentication and reach internal services normally protected by it.
Fix
Patch to the fixed NetScaler versions, review configurations against Citrix's exposure criteria, monitor these appliances closely for compromise given their history as targets, and restrict management and gateway exposure where possible.