The Cybersecurity and Infrastructure Security Agency requires U.S. federal agencies to mitigate or discontinue use of Citrix NetScaler products by September 12, 2026. The requirement applies to an authentication-bypass vulnerability identified as CVE-2026-19490 in Citrix NetScaler ADC and NetScaler Gateway appliances.

The vulnerability allows unauthenticated remote actors to bypass security controls when the appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy configurations. Agencies must apply mitigations in accordance with vendor instructions and comply with CISA Binding Operational Directive 26-04 regarding prioritizing security updates based on risk.

Agencies must discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to patching guidelines outlined in Binding Operational Directive 26-04.

CISA has designated forensic triage as a required action for this vulnerability. Known ransomware campaign use of this vulnerability is currently unknown.

Timeline

On September 30, 2022, NetScaler was formed as a business unit under the Cloud Software Group when Citrix was taken private as part of a merger with TIBCO Software. On September 9, 2026, the requirement applied to an authentication-bypass vulnerability identified as CVE-2026-19490 in Citrix NetScaler ADC and NetScaler Gateway appliances. Agencies were required to apply mitigations in accordance with vendor instructions and comply with CISA Binding Operational Directive 26-04 regarding prioritizing security updates based on risk.

The Cybersecurity and Infrastructure Security Agency required U.S. federal agencies to mitigate or discontinue use of Citrix NetScaler products by September 12, 2026. CISA announced vulnerabilities in Cisco Firewall Management Center, Fortinet multiple products, and Google Chromium V8 in the same batch on September 9, 2026. Agencies were required to discontinue use of the product if mitigations were unavailable, and CISA designated forensic triage as a required action for this vulnerability. This marked the 13th comparable security event announced by CISA in the last year.

What's New

CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities (KEV) Catalog on Monday, ordering Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by August 29, as mandated by Binding Operational Directive (BOD) 26-04. In July 2023, CISA added CVE-2023-3519 to its Known Exploited Vulnerabilities Catalog, which was an unauthenticated remote code execution vulnerability affecting NetScaler ADC and NetScaler Gateway. Threat actors exploited this vulnerability as a zero-day to drop a webshell on a critical infrastructure organization’s non-production environment NetScaler ADC appliance.

Why It Matters

The directive represents the 13th comparable security event announced by CISA in the last year, indicating a sustained pattern of vulnerabilities affecting critical networking infrastructure. The agency simultaneously addressed flaws in Cisco Firewall Management Center, Fortinet multiple products, and Google Chromium V8.

Previous exploitation of NetScaler products demonstrates the tangible risk associated with these vulnerabilities. In July 2023, threat actors used a zero-day exploit to drop a webshell on a critical infrastructure organization’s appliance, establishing a precedent for active exploitation that informs the current mandatory mitigation and discontinuation requirements.