LATEST View all updates

NetScaler CVE-2026-19490 Added to CISA KEV: Check Affected Builds and Patch

CISA added NetScaler CVE-2026-19490 to KEV. Check affected builds, configuration conditions and patch status now.

NetScaler CVE-2026-19490 editorial security image showing an enterprise gateway under active exploitation alert

Signal Brief

  • CISA added NetScaler CVE-2026-19490 to KEV on September 9, making known exploitation the current security state.
  • Exposure depends on both the NetScaler build and CVE-specific Gateway, AAA or applicable SAML configuration conditions.
  • Reviewed fixed thresholds include 14.1-73.32 or later and 13.1-63.21 or later, with separate vendor guidance for FIPS and NDcPP branches.
  • Patching verifies the current remediation state but does not prove an appliance was never compromised before the update.

NetScaler CVE-2026-19490 is now in the CISA Known Exploited Vulnerabilities catalog, changing the security state from a critical patched vulnerability to one with confirmed exploitation in the wild. Administrators should not decide exposure from the product name alone: the relevant NetScaler branch, installed build and configuration conditions all matter.

Current answer: if you manage a customer-controlled NetScaler ADC or NetScaler Gateway, identify the exact running build and check whether the appliance meets the vendor’s CVE-2026-19490 configuration preconditions. Affected systems should be upgraded to the relevant fixed build or a later supported release. Installing the fix establishes the current remediation state but does not prove the appliance was never exploited before patching.

What changed with NetScaler CVE-2026-19490

The important new development is the exploitation state. NetScaler had already disclosed CVE-2026-19490 as a critical authentication-bypass vulnerability and published fixed builds. On September 9, 2026, CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, according to current government cyber guidance. That makes active exploitation part of the current risk assessment rather than a theoretical possibility.

The reviewed evidence does not establish the threat actor, campaign size, affected organizations or India-specific victim count. TPS also has not verified a complete CVE-2026-19490-specific indicator-of-compromise list. Those points should remain unresolved unless controlling security sources publish additional evidence.

Which NetScaler builds need attention?

NetScaler’s current security bulletin identifies affected customer-managed branches and the corresponding fixed releases. For the commonly deployed branches reviewed for this article, NetScaler ADC and Gateway 14.1 should be on 14.1-73.32 or later, while 13.1 should be on 13.1-63.21 or later. The vendor bulletin also provides corresponding fixed releases for applicable FIPS and NDcPP branches.

A version number is only one part of the exposure decision. CVE-2026-19490 has configuration preconditions involving NetScaler Gateway or AAA virtual-server use, and the exact condition differs across certain branches. On specified newer branches, the presence of a SAML action is also relevant. Administrators should therefore compare both the deployed build and the vendor-defined configuration state instead of assuming that every appliance on a named branch is equally exposed.

NetScaler CVE-2026-19490 decision path

1. Identify the exact NetScaler branch and build

Record the running ADC or Gateway release before selecting a remediation path. Do not rely only on the major branch number.

2. Check the CVE-specific configuration conditions

Determine whether the appliance is configured with the Gateway or AAA virtual-server conditions described by NetScaler. For relevant branches, verify whether the SAML-related condition also applies.

3. Compare the build with the fixed threshold

For the reviewed mainstream branches, 14.1-73.32 and 13.1-63.21 are the vendor fixed thresholds. Use the current NetScaler bulletin for FIPS, NDcPP and any later branch-specific guidance.

4. Upgrade when the appliance is affected

NetScaler’s bulletin does not provide a workaround that removes the vulnerability. Affected customers should install the appropriate fixed or later supported release.

5. Verify the resulting state

After remediation, confirm that the appliance is actually running the intended fixed build. A planned or downloaded update is not the same as a verified deployed version.

6. Treat earlier exposure as a separate question

Patching closes the known vulnerable software state going forward. It does not retrospectively demonstrate that exploitation did not occur before remediation.

Why CVE-2026-19490 should not be confused with CVE-2026-19489

The two CVEs appeared in the same NetScaler security cycle, but they are not the same technical problem. CVE-2026-19490 is the authentication-bypass issue relevant to this article. CVE-2026-19489 is a separate memory-overflow denial-of-service vulnerability with different technical conditions. Operators should not mix the affected-state logic or remediation explanation for the two flaws.

This is also separate from NetScaler CVE-2026-8452

TPS previously covered actively exploited NetScaler CVE-2026-8452. CVE-2026-19490 is a distinct vulnerability with a separate event, configuration boundary and fixed-build state. The fact that both affect NetScaler appliances and require version verification does not make them the same canonical security issue.

Does patching prove the appliance is clean?

No. Updating an affected NetScaler appliance establishes that the currently installed software has moved beyond the vendor’s vulnerable build boundary. It cannot by itself determine whether an appliance was exploited before the update. Organizations with evidence of suspicious activity or meaningful pre-patch exposure may need to use current NetScaler forensic and indicator-of-compromise guidance and their normal incident-response process.

TPS is not treating NetScaler’s general compromise-detection tooling as a complete CVE-2026-19490-specific IOC checklist. CVE-specific campaign evidence and comprehensive forensic indicators remain unresolved in the sources reviewed for this article.

What to watch next

The next material update could come from CISA or another national cyber authority, a revision to NetScaler’s bulletin, new exploitation details, CVE-specific indicators of compromise, forensic guidance or a change to fixed-build recommendations. Any of those developments could materially change the current reader action or compromise-assessment boundary.

Verification note

ThePulseSignal reviewed NetScaler’s security bulletin and current government cyber guidance confirming the September 9 CISA KEV addition, then reconciled the vulnerability’s affected-version thresholds with its configuration-specific exposure conditions. The active-exploitation state, vendor fixed builds and need for configuration-aware verification are supported; campaign scope and individual compromise remain unresolved.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led informational and editorial guidance to help NetScaler administrators assess CVE-2026-19490 exposure and remediation. CISA KEV inclusion confirms known exploitation, but the reviewed evidence does not establish the attacker, victim scope, India-specific incidents, complete CVE-specific indicators of compromise or whether any individual appliance was compromised. Verify your exact NetScaler build and configuration against controlling current NetScaler and government security guidance before consequential security action.