Citrix NetScaler CVE-2026-19490 Exploitation Attempts Detected in the Wild
Attackers have started targeting a critical-severity authentication bypass vulnerability in Citrix NetScaler appliances, according to vulnerability intelligence firm Previdian.
Tracked as CVE-2026-19490, the security flaw could allow an unauthenticated remote attacker to bypass authentication when a NetScaler appliance is configured as a AAA virtual server or gateway. Affected configurations may include SSL VPN, ICA Proxy, CVPN, and RDP Proxy deployments, depending on the NetScaler firmware version and whether SAML actions are configured.
Citrix addressed the vulnerability in mid-August and urged customers to review the official NetScaler ADC and NetScaler Gateway security bulletin. Administrators should determine whether their deployments are affected and upgrade vulnerable appliances to the recommended firmware build as soon as possible.
Citrix has not confirmed that CVE-2026-19490 has been successfully exploited. However, Previdian founder and security researcher Ryan Dewhurst told BleepingComputer that attackers are beginning to target CVE-2026-19490 in the wild after a credible proof-of-concept exploit was published online.
“On September 3rd, one of our NetScaler sensors received requests matching the PoC from three different source IPs geographically located in Australia, the United States, and Germany,” Dewhurst told BleepingComputer.
“Our current assessment is that this provides evidence of an attempted exploit, but does not support a successful compromise of a real-world system.”

The Belgian Cybersecurity Center and the Belgian National Cybersecurity Coordination Center (NCC-BE) warned on Friday that exploitation attempts targeting CVE-2026-19490 were increasing. The organizations urged administrators to prioritize patching all vulnerable Citrix NetScaler appliances connected to their networks.
Internet threat monitoring group Shadowserver tracks more than 22,000 NetScaler ADC appliances and approximately 1,700 NetScaler gateways exposed online. However, the data does not indicate how many systems are honeypots, whether they use vulnerable configurations, or whether they have already been patched against CVE-2026-19490.
Citrix also warned administrators about two additional NetScaler vulnerabilities, CVE-2026-3055 and CVE-2026-4368, in March. Threat actors began exploiting the flaws in attacks only days after the vulnerabilities were disclosed.
The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-3055 to its Known Exploited Vulnerabilities Catalog a week later. Federal agencies were instructed to patch vulnerable Citrix appliances within three days.
Since November 2021, the U.S. cybersecurity agency has listed 23 Citrix vulnerabilities in its catalog, including six vulnerabilities that have been exploited by ransomware groups.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



