A Critical Citrix Flaw is Now Being Exploited in Real-World Attacks
Citrix, a leading provider of secure networking solutions, has had its NetScaler appliance vulnerability exploited by attackers. The flaw, known as CVE-2026-19490, allows unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured in certain ways. This means that even if users try to log in with their credentials, they may not be able to access the system.
The issue was first discovered by Citrix in mid-August and a security bulletin was issued urging admins to patch the vulnerability as soon as possible. However, according to Previdian, a vulnerability intelligence company, attackers have already begun targeting this flaw in real-world attacks. The company’s founder, Ryan Dewhurst, reported that his team had seen requests matching the proof-of-concept exploit from three different source IPs located in Australia, the United States, and Germany.
This is not an isolated incident, as Citrix has been plagued by vulnerabilities over the past year. In March, the company urged admins to patch two other NetScaler flaws (CVE-2026-3055 and CVE-2026-4368) just days before threat actors began exploiting them in attacks. The Cybersecurity and Infrastructure Security Agency (CISA) added the CVE-2026-3055 flaw to its catalog of actively exploited vulnerabilities and ordered federal agencies to patch vulnerable Citrix appliances within three days.
The fact that attackers have begun exploiting this vulnerability is a clear indication that users should take immediate action to protect their systems. With over 22,000 NetScaler ADC appliances and nearly 1,700 Gateway instances exposed online, there is a significant risk of compromise if the vulnerability is not patched. Citrix has urged admins to review the official security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible.
The exploitation of this vulnerability also highlights the importance of regular patching and updates. As seen in previous incidents, attackers often target vulnerabilities that have been known for some time but not yet patched. In this case, the proof-of-concept exploit was published online, which likely contributed to the rapid exploitation by attackers. By keeping systems up-to-date with the latest patches, users can significantly reduce their risk of being compromised.
To protect against this vulnerability, admins should prioritize patching all vulnerable Citrix NetScaler appliances on their networks as soon as possible. This includes reviewing the official security bulletin and assessing whether their deployments are affected. Additionally, users should ensure that their systems are configured securely to prevent exploitation attempts. By taking these steps, organizations can reduce their risk of being compromised by this critical flaw.
Source: Bleeping Computer — 2026-09-04