Attackers have begun targeting a critical Citrix NetScaler auth bypass vulnerability after a public proof-of-concept exploit emerged online. Administrators should review exposed appliances and apply Citrix’s recommended updates without delay.
CVE-2026-19490 allows remote authentication bypass
Tracked as CVE-2026-19490, the flaw can allow unauthenticated attackers to bypass login protections remotely.
The vulnerability affects NetScaler appliances configured as AAA virtual servers or Gateway deployments. This includes SSL VPN, ICA Proxy, CVPN and RDP Proxy configurations. Exposure depends on the firmware version and whether SAML Action is enabled.
Citrix addressed the issue in a security bulletin released in mid-August. At the time, the company urged customers to assess their environments and upgrade affected systems as soon as possible.
Security researchers observe exploit attempts
Vulnerability intelligence firm Previdian says it has observed attempts to exploit CVE-2026-19490 in the wild.
According to founder Ryan Dewhurst, one of the company’s NetScaler sensors received requests matching the published proof of concept on September 3. The requests came from three distinct IP addresses geolocated to Australia, the United States and Germany.
The activity provides evidence of exploitation attempts. However, it does not confirm that attackers successfully compromised any real-world organisations.
Belgium’s national cybersecurity coordination centre has also warned that threat actors are targeting the flaw. It urged administrators to prioritise patching vulnerable Citrix NetScaler appliances.
Thousands of NetScaler systems remain exposed
Internet scanning data shows that more than 22,000 NetScaler ADC appliances and almost 1,700 NetScaler Gateway instances are exposed online.
It remains unclear how many are vulnerable, patched or operating as honeypots. Still, the number of exposed devices gives attackers a substantial pool of potential targets.
Citrix NetScaler appliances have repeatedly attracted attackers in recent years. In March, Citrix urged customers to patch two other serious vulnerabilities shortly before threat actors began exploiting them.
Since November 2021, CISA has recorded 23 Citrix vulnerabilities as exploited in the wild. Ransomware groups have abused six of those flaws.
The Citrix NetScaler auth bypass should now be treated as an urgent patching priority, especially for internet-facing systems.


0 responses to “Critical Citrix NetScaler auth bypass now targeted in attacks”