Organizations should immediately apply vendor-provided patches for the listed vulnerabilities. For CVE-2019-1068, Citrix has released updates; consult official advisories. Additionally, monitor CISA's KEV catalog for updates and implement compensating controls if patches cannot be applied immediately. Federal agencies must comply with BOD 22-01 deadlines.
Quick answers
What is CVE-2019-1068?
Organizations should immediately apply vendor-provided patches for the listed vulnerabilities. For CVE-2019-1068, Citrix has released updates; consult official advisories. Additionally, monitor CISA's KEV catalog for updates and implement compensating controls if patches cannot be applied immediately. Federal agencies must comply with BOD 22-01 deadlines.
How severe is CVE-2019-1068?
high
Is CVE-2019-1068 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2019-1068 be mitigated?
Organizations should immediately apply vendor-provided patches for the listed vulnerabilities. For CVE-2019-1068, Citrix has released updates; consult official advisories. Additionally, monitor CISA's KEV catalog for updates and implement compensating controls if patches cannot be applied immediately. Federal agencies must comply with BOD 22-01 deadlines.
CVSS
—
Vendor
Citrix
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
NetScaler ADC, NetScaler Gateway
Mitigation
Organizations should immediately apply vendor-provided patches for the listed vulnerabilities. For CVE-2019-1068, Citrix has released updates; consult official advisories. Additionally, monitor CISA's KEV catalog for updates and implement compensating controls if patches cannot be applied immediately. Federal agencies must comply with BOD 22-01 deadlines.
The Cybersecurity and Infrastructure Security Agency (CISA) has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation in the wild. The newly listed flaws affect Red Hat libuser and Automatic Bug Reporting Tool, Microsoft SQL Server, Ajax.NET Professional, the Linux kernel, and Citrix NetScaler ADC and Gateway products. CISA's Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of these KEV-listed vulnerabilities on publicly exposed assets, particularly those that grant total control post-exploitation.
CISA has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The list includes a high-severity remote code execution flaw in Citrix NetScaler ADC and NetScaler Gateway (CVE-2019-1068), along with bugs affecting Linux and Microsoft SQL Server. Organizations are urged to apply patches immediately.