A critical-severity authentication bypass vulnerability in Citrix NetScaler, tracked as CVE-2026-19490, is being actively exploited in the wild. Vulnerability intelligence company Previdian reported that attackers have begun targeting this flaw. The vulnerability allows threat actors to bypass authentication mechanisms in Citrix NetScaler products. Given its critical severity rating and active exploitation, organizations using Citrix NetScaler are at significant risk. This type of auth bypass flaw can enable unauthorized access to sensitive systems and networks. Immediate patching or mitigation is strongly recommended for affected deployments.
CVE-2026-19490 is a critical-severity authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway. It allows unprivileged remote threat actors to bypass authentication when the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy). Exploitability depends on the NetScaler firmware version and whether SAML Action is configured. Citrix disclosed and patched the flaw in mid-August 2026 via security advisory CTX696939. A credible proof-of-concept (PoC) exploit was subsequently published online, triggering active exploitation attempts. On September 3, Previdian's NetScaler honeypot sensors detected requests matching the PoC from three distinct source IPs geolocated to Australia, the United States, and Germany. As of reporting, exploitation attempts have been observed but successful compromise of real-world systems has not been confirmed. Over 22,000 NetScaler ADC appliances and nearly 1,700 Gateway instances are exposed on the internet according to Shadowserver. Since November 2021, CISA has tagged 23 Citrix vulnerabilities as exploited in the wild, six of which have been abused by ransomware gangs.
1. Review the official Citrix NetScaler ADC and NetScaler Gateway security bulletin (CTX696939) immediately. 2. Assess whether your deployments are affected based on configuration (AAA virtual server or Gateway modes including SSL VPN, ICA Proxy, CVPN, RDP Proxy) and firmware version. 3. Upgrade all impacted appliances to the recommended builds as soon as possible. 4. Prioritize patching all vulnerable Citrix NetScaler appliances on your network as urged by the Centre for Cybersecurity Belgium (CCB/NCC-BE). 5. Monitor for exploitation attempts matching the published PoC patterns. 6. Check CISA's Known Exploited Vulnerabilities catalog for any updates on CVE-2026-19490 and related Citrix CVEs. 7. Limit internet exposure of NetScaler ADC and Gateway instances where possible until patched.
Source IPs geolocated to Australia targeting CVE-2026-19490 (observed September 3), Source IPs geolocated to United States targeting CVE-2026-19490 (observed September 3), Source IPs geolocated to Germany targeting CVE-2026-19490 (observed September 3)