Skip to content

Claude Desktop cisa cybersecurity mcp server Resource/CVE-2026-19490 — Citrix NetScaler Authentication Bypass Using an Altern…

How to: Claude Desktop cisa cybersecurity mcp server CVE-2026-19490 — Citrix NetScaler Authentication Bypass Using an Altern…

client:Claude Desktop transport:streamable-http resource:CVE-2026-19490 — Citrix NetScaler Authentication Bypass Using an Altern…

Add cisa cybersecurity mcp server to Claude Desktop

  1. 01

    Open ~/Library/Application Support/Claude/claude_desktop_config.json and merge this in. Keep any servers already there.

{
  "mcpServers": {
    "cisa-cybersecurity-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://cisa-cybersecurity.caseyjhand.com/mcp"
      ]
    }
  }
}
  1. 02

    Save the file and restart Claude Desktop.

  2. 03

    CVE-2026-19490 — Citrix NetScaler Authentication Bypass Using an Altern… is surfaced in the attachment menu, where you pick it as context. It is context to attach, not an action to run.

  3. 04

    If it does not appear, check that cisa cybersecurity mcp server is connected and that you are looking at its resources rather than its tools.

Claude Desktop has no remote transport in its config file, so this bridges through mcp-remote. Restart the app after saving. Claude Desktop docs

Set these first

cisa cybersecurity mcp server will not start until these are set, so it never reaches Claude Desktop.

  • MCP_LOG_LEVEL
  • CISA_KEV_REFRESH_CRON
  • CISA_CSAF_MIRROR_PATH
  • CISA_CSAF_MIRROR_AUTO_INIT
  • CISA_CSAF_REFRESH_CRON
  • CISA_VULNRICHMENT_CACHE_TTL_SECONDS
  • CISA_FEED_CACHE_TTL_SECONDS
  • CISA_HTTP_TIMEOUT_MS

Same resource, other clients

Read from the server itself, by connecting to it and calling resources/list on 24 September 2026. A listing does not declare its resources, so asking is the only way to know them, and this is what the server actually offers rather than what its listing claims. Names only are stored; connect the server for each resource's type and contents.