Cyber Resilience
← All news
Confirmed

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

Our takeCISA's Saturday deadline binds federal agencies, but active exploitation doesn't check your sector: CVE-2026-19490 in Citrix NetScaler ADC/Gateway is being used for remote code execution now. If you run NetScaler, patch on CISA's timeline, not your own — and check for compromise.
Sources (4)
What this means for you — Security leader:CISA has directed all U.S. federal agencies to remediate the actively exploited Citrix NetScaler RCE (CVE-2026-19490) by Saturday. If you operate NetScaler ADC or Gateway in your environment, treat this as an emergency patch and scan for indicators of compromise immediately.
What this means for you — Lean IT orgs:If you run a Citrix NetScaler ADC or Gateway appliance, apply the vendor patch this week. The U.S. government considers the remote code execution flaw actively exploited in attacks.
What this means for you — MSP:Check every client running Citrix NetScaler ADC or Gateway and ensure the patch for CVE-2026-19490 is applied no later than Saturday. Hunt for signs of exploitation on unpatched instances.
What this means for you — Researcher:CISA added the Citrix NetScaler unauthenticated RCE (CVE-2026-19490) to its KEV catalog with a binding federal deadline of Saturday. Canadian CCCS also issued AL26-019 on the same pair of vulnerabilities.