Key Facts
SecurityWeek reports that CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog after observing exploitation. The report says Previdian data indicates exploitation since at least September 3 and an exploit was published on GitHub the previous day.
Technical Details
NetScaler’s bulletin describes CVE-2026-19490 as authentication bypass using an alternate path. It affects specified NetScaler ADC and Gateway deployments configured as a Gateway or AAA virtual server, subject to version-specific conditions; the vendor assigns a CVSS v4 base score of 9.3.
Impact & Mitigation
Upgrade affected customer-managed instances to the fixed NetScaler builds listed by the vendor, including 14.1-73.32 or later and 13.1-63.21 or later where applicable. The bulletin states there are no workarounds; verify whether the documented Gateway, AAA, and SAML configuration preconditions apply.
Sources
- NetScaler security bulletin CTX696939
- SecurityWeek exploitation report
- Previdian CVE-2026-19490 telemetry
