Citrix NetScaler Auth Bypass Now Used in Active Attacks

▼ Summary
– Attackers are actively exploiting a critical Citrix NetScaler vulnerability, CVE-2026-19490, which allows remote authentication bypass.
– Security researchers detected exploitation attempts from multiple countries after a proof-of-concept exploit was published online.
– Citrix and various cybersecurity agencies have urged administrators to urgently patch their NetScaler appliances to mitigate the risk.
– While evidence of exploitation exists, it has not yet been confirmed that real-world systems have been successfully compromised.
– This incident follows previous warnings about unpatched Citrix flaws being rapidly exploited by threat actors in the wild.
Active Exploitation of Critical Citrix Flaw
Security researchers have confirmed that threat actors are actively targeting a critical-severity vulnerability in Citrix NetScaler devices. According to intelligence from Previdian, the flaw, tracked as CVE-2026-19490, is being exploited in the wild following the public release of a proof-of-concept (PoC) exploit. This security breach allows unprivileged attackers to bypass authentication remotely on appliances configured as an AAA virtual server or specific Gateway types, including SSL VPN, ICA Proxy, CVPN, and RDP Proxy. The successful exploitation depends heavily on the specific NetScaler firmware version and whether SAML Action is configured.
Ryan Dewhurst, founder of Previdian, provided BleepingComputer with evidence of these attacks occurring just days after the PoC was made available online. Dewhurst noted that his team’s sensors detected malicious traffic originating from multiple countries. “On 3 September, one of our NetScaler sensors received requests matching the PoC from three distinct source IPs, geolocated to Australia, the United States and Germany,” Dewhurst told BleepingComputer. He clarified the severity of the situation, stating, “Our current assessment is that this provides evidence of exploitation attempts, but does not confirm successful compromise of real-world systems.”
Urgent Patching Recommendations
The urgency of the situation is underscored by warnings from both Citrix and international cybersecurity bodies. In mid-August, when the vendor initially addressed the issue, they issued a stark warning to administrators. “We strongly recommend that customers review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,” Citrix warned.
This sentiment was echoed by the Centre for Cybersecurity Belgium (NCC-BE), which urged organizations to prioritize patching all vulnerable Citrix NetScaler appliances immediately. While Shadowserver monitors over 22,000 exposed NetScaler ADC appliances and nearly 1,700 Gateway instances globally, it remains unclear how many of these are honeypots, possess vulnerable configurations, or have already been secured against CVE-2026-19490.
Historical precedents suggest that delays in patching can lead to rapid exploitation. In March, Citrix advised admins to fix two other flaws, CVE-2026-3055 and CVE-2026-4368, only for threat actors to begin exploiting them shortly thereafter. The Cybersecurity and Infrastructure Security Agency (CISA) subsequently added CVE-2026-3055 to its list of actively exploited vulnerabilities, mandating that federal agencies patch affected systems within three days. Since November 2021, CISA has identified 23 Citrix vulnerabilities as being exploited in the wild, with six of those also being abused by ransomware groups.
(Source: BleepingComputer)




