• News/
  • bleepingcomputer-20260904152559

Critical Citrix NetScaler auth bypass now leveraged in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Sep 4, 2026
·
Updated

Attackers have begun targeting a critical-severity Citrix NetScaler flaw in the wild, according to vulnerability intelligence company Previdian. Tracked as CVE-2026-19490, this security flaw can allow unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured. "We strongly recommend that customers review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible," Citrix warned in mid-August when it addressed the flaw and urged admins to patch it as soon as possible. While the company has yet to flag the vulnerability as actively exploited in its August 19 security advisory, Previdian founder and security researcher Ryan Dewhurst told BleepingComputer on Thursday that attackers have begun targeting CVE-2026-19490 in the wild after a "credible" proof-of-concept exploit was published online. "On 3 September, one of our NetScaler sensors received requests matching the PoC from three distinct source IPs, geolocated to Australia, the United States and Germany," Dewhurst told BleepingComputer. "Our current assessment is that this provides evidence of exploitation attempts, but it does not confirm successful compromise of real-world systems."

The...

Read full article

Affected Software

2 affected components
Citrix NetScaler ADC
Citrix NetScaler Gateway

Frequently Asked Questions

1

Which NetScaler deployments may be vulnerable to CVE-2026-19490?

The flaw can affect NetScaler appliances configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, and RDP Proxy. Exposure depends on the NetScaler firmware version and whether SAML Action is configured.

2

What should administrators do to address this issue?

Citrix recommends reviewing the official NetScaler ADC and NetScaler Gateway security bulletin, determining whether deployments are affected, and upgrading impacted appliances to the recommended builds as soon as possible.

3

Is exploitation of CVE-2026-19490 confirmed by Citrix?

Citrix had not marked the flaw as actively exploited in its August 19 advisory. However, Previdian founder Ryan Dewhurst told BleepingComputer that attackers began targeting it after a credible proof-of-concept exploit was published online, and the vulnerability is listed as exploited.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203