Critical Citrix NetScaler auth bypass now leveraged in attacks

Critical Citrix NetScaler Flaw Exploited in Real-World Attacks, Experts Warn

Citrix’s NetScaler appliance has been compromised by attackers exploiting a critical vulnerability that allows unprivileged threat actors to bypass authentication remotely. This flaw, tracked as CVE-2026-19490, was first disclosed in mid-August and has now been confirmed to be exploited in the wild.

The vulnerability affects Citrix NetScaler appliances configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the firmware version and SAML Action configuration. Once exploited, attackers can gain unauthorized access to sensitive data and systems. This is particularly concerning given the widespread adoption of NetScaler appliances in organizations worldwide.

According to Previdian’s vulnerability intelligence, a “credible” proof-of-concept exploit was published online, which has now been leveraged by attackers in real-world attacks. The company’s founder, Ryan Dewhurst, revealed that three distinct source IPs from Australia, the United States, and Germany had attempted to exploit the flaw on September 3rd. While this does not confirm successful compromises of real-world systems, it is clear that threat actors are actively targeting CVE-2026-19490.

The Centre for Cybersecurity Belgium has also warned of exploitation attempts and urged administrators to prioritize patching all vulnerable Citrix NetScaler appliances on their networks. The warning highlights the importance of staying up-to-date with security patches, particularly when vulnerabilities are known to be exploited in the wild.

Citrix’s recent history of vulnerability disclosures is concerning. In March, the company warned administrators to patch two other NetScaler flaws (CVE-2026-3055 and CVE-2026-4368) just days before threat actors began exploiting them in attacks. The US Cybersecurity and Infrastructure Security Agency (CISA) added the CVE-2026-3055 flaw to its catalog of actively exploited vulnerabilities one week later, ordering federal agencies to patch vulnerable Citrix appliances within three days.

This latest incident underscores the need for organizations to prioritize vulnerability management and patching. With so many NetScaler appliances exposed online – over 22,000 ADC instances and nearly 1,700 Gateway instances – it is essential that administrators take immediate action to mitigate this risk.

In light of these findings, we recommend that all Citrix administrators review their deployment configurations and assess whether they are affected by the CVE-2026-19490 vulnerability. If vulnerable, it is crucial to upgrade impacted appliances to the recommended builds as soon as possible.


Source: Bleeping Computer — 2026-09-04