Back to feed

Attackers exploit critical Citrix NetScaler authentication bypass CVE-2026-19490

2 min
Attackers exploit critical Citrix NetScaler authentication bypass CVE-2026-19490

This digest was compiled by AI from multiple sources — links to the originals are below.

Attackers have begun exploiting a critical Citrix NetScaler authentication bypass flaw tracked as CVE-2026-19490. Previdian detected exploitation attempts from IPs in Australia, the United States, and Germany on September 3. Citrix and Belgium's cybersecurity centre urge immediate patching of affected appliances.

Key Facts

  • CVE-2026-19490 allows unprivileged attackers to bypass authentication remotely on NetScaler appliances configured as AAA virtual servers or Gateways.
  • Previdian detected exploitation attempts from three IPs in Australia, the United States, and Germany on September 3.
  • Citrix addressed the flaw in mid-August and urged administrators to upgrade impacted appliances.
  • Shadowserver tracks over 22,000 NetScaler ADC appliances and nearly 1,700 Gateway instances exposed online.
  • CISA has tagged 23 Citrix vulnerabilities as exploited in the wild since November 2021, six by ransomware gangs.

Exploitation Attempts

Previdian founder Ryan Dewhurst told BleepingComputer that attackers began targeting CVE-2026-19490 after a credible proof-of-concept exploit was published online. On September 3, one NetScaler sensor received requests matching the PoC from three distinct source IPs geolocated to Australia, the United States, and Germany. Dewhurst assessed that this provides evidence of exploitation attempts but does not confirm successful compromise of real-world systems. The Centre for Cybersecurity Belgium warned on Friday of exploitation attempts targeting CVE-2026-19490 and urged administrators to prioritize patching.

Vulnerability Details

CVE-2026-19490 can allow unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured as an AAA virtual server or as a Gateway. The flaw's impact depends on the NetScaler firmware version and whether SAML Action is configured. Citrix warned in mid-August that customers should review the official security bulletin and upgrade impacted appliances to recommended builds as soon as possible. Shadowserver tracks over 22,000 NetScaler ADC appliances and nearly 1,700 Gateway instances exposed online, though the number of vulnerable or patched systems is unknown.

Patching Urgency

Citrix urged administrators to patch two other NetScaler flaws, CVE-2026-3055 and CVE-2026-4368, in March, days before threat actors began exploiting them. CISA added CVE-2026-3055 to its catalog of actively exploited vulnerabilities one week later and ordered federal agencies to patch within three days. Since November 2021, CISA has tagged 23 Citrix vulnerabilities as exploited in the wild, six of which have also been abused by ransomware gangs.

1 source

Time · lag behind first