Critical Citrix NetScaler Flaw Actively Exploited In The Wild
A critical authentication bypass vulnerability, **CVE-2026-19490**, affecting **Citrix NetScaler ADC** and **NetScaler Gateway** appliances, is now being actively exploited. Security professionals are urged to prioritize patching immediately to prevent unauthorized remote access.
Attackers have begun targeting a critical-severity **Citrix NetScaler** flaw in the wild, according to vulnerability intelligence company **Previdian**.
Tracked as **CVE-2026-19490**, this security flaw can allow unprivileged threat actors to bypass authentication remotely. This is possible when the **NetScaler** appliance is configured as an **AAA virtual server** or as a **Gateway** (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the **NetScaler** firmware version and whether **SAML Action** is configured.
**Citrix** warned in mid-August, when it addressed the flaw, urging admins to patch it as soon as possible. "We strongly recommend that customers review the official **NetScaler ADC** and **NetScaler Gateway** security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible," **Citrix** stated.
### Evidence of Exploitation
While **Citrix** has yet to flag the vulnerability as actively exploited in its August 19 security advisory, **Previdian** founder and security researcher **Ryan Dewhurst** confirmed that attackers have begun targeting **CVE-2026-19490** after a "credible" proof-of-concept exploit was published online.
"On 3 September, one of our **NetScaler** sensors received requests matching the PoC from three distinct source IPs, geolocated to Australia, the United States and Germany," **Dewhurst** told BleepingComputer. "Our current assessment is that this provides evidence of exploitation attempts, but it does not confirm successful compromise of real-world systems."

### Urgent Call to Action
The **Centre for Cybersecurity Belgium (CCB)**, the country's National Cybersecurity Coordination Centre for Belgium (**NCC-BE**), also warned of exploitation attempts targeting **CVE-2026-19490**. They urged admins to prioritize patching all vulnerable **Citrix NetScaler** appliances on their organizations' networks.
Internet threat watchdog **Shadowserver** tracks over 22,000 **NetScaler ADC** appliances and nearly 1,700 **Gateway** instances exposed online. However, it remains unclear how many of these are honeypots, have vulnerable configurations, or have already been patched against **CVE-2026-19490** attacks.
### A Recurring Pattern
This isn't the first time **Citrix** has had to issue urgent patching advice for its **NetScaler** products. In March, **Citrix** urged admins to patch two other **NetScaler** flaws (**CVE-2026-3055** and **CVE-2026-4368**) just days before threat actors began exploiting them.
The **Cybersecurity and Infrastructure Security Agency (CISA)** added the **CVE-2026-3055** flaw to its catalog of actively exploited vulnerabilities one week later, ordering federal agencies to patch vulnerable **Citrix** appliances within three days. Since November 2021, **CISA** has tagged 23 **Citrix** vulnerabilities as exploited in the wild, with six also abused by ransomware gangs.