Attackers Exploit Critical Citrix NetScaler Authentication Bypass Flaw

Attackers have begun actively targeting a critical-severity Citrix NetScaler vulnerability tracked as CVE-2026-19490, according to vulnerability intelligence company Previdian. The flaw allows unprivileged threat actors to remotely bypass authentication when a NetScaler appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, and RDP Proxy setups. Citrix addressed the issue in mid-August and urged administrators to upgrade affected appliances to the recommended builds as soon as possible.

Previdian founder Ryan Dewhurst tells BleepingComputer that exploitation attempts began after a credible proof-of-concept exploit appears online. On September 3, Previdian's NetScaler sensors receive requests matching the PoC from three distinct source IPs geolocated to Australia, the United States, and Germany. While this provides evidence of exploitation attempts, Dewhurst notes it does not confirm successful compromise of real-world systems. The Centre for Cybersecurity Belgium also warns of the attacks and urges administrators to prioritize patching all vulnerable appliances.

Shadowserver currently tracks over 22,000 NetScaler ADC appliances and nearly 1,700 Gateway instances exposed online, though it remains unclear how many run vulnerable configurations or have already been patched. The urgency is heightened by history: Citrix patched two other NetScaler flaws in March, CVE-2026-3055 and CVE-2026-4368, just days before threat actors begin exploiting them, and CISA adds CVE-2026-3055 to its catalog of actively exploited vulnerabilities. Organizations running NetScaler are strongly encouraged to review Citrix's security bulletin and apply updates immediately.

Read More at the original source →