Attackers have begun targeting a critical Citrix NetScaler authentication-bypass vulnerability in the wild, according to vulnerability intelligence company Previdian.
Tracked as CVE-2026-19490, the flaw can allow unprivileged threat actors to bypass authentication remotely when a NetScaler appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy. Exploitability depends on the NetScaler firmware version and whether SAML Action is configured.
Citrix addressed the vulnerability in mid-August and urged customers to review its official NetScaler ADC and NetScaler Gateway security bulletin, assess affected deployments, and upgrade impacted appliances to recommended builds. The company had not identified CVE-2026-19490 as actively exploited in its 19 August security advisory.
However, Previdian founder and security researcher Ryan Dewhurst told BleepingComputer that attackers began targeting the flaw after a credible proof-of-concept exploit was published online. On 3 September, one Previdian NetScaler sensor received requests matching the proof of concept from three source IPs geolocated to Australia, the United States, and Germany. Dewhurst said the activity indicates exploitation attempts but does not confirm successful compromise.
The Centre for Cybersecurity Belgium also warned of exploitation attempts. Shadowserver tracks more than 22,000 exposed NetScaler ADC appliances and nearly 1,700 Gateway instances, though the number with vulnerable configurations or unpatched systems is unknown.
Comments
0No comments yet. Be the first to comment.