Attackers are targeting a critical Citrix NetScaler vulnerability that can allow remote authentication bypass, security researchers have warned, although there is currently no evidence that the activity has led to successful compromises.
The flaw, tracked as CVE-2026-19490, affects NetScaler appliances configured as an AAA virtual server or as a Gateway service, including SSL VPN, ICA Proxy, CVPN and RDP Proxy deployments. Its impact depends on the firmware version and whether SAML Action is configured.
Previdian, a vulnerability intelligence company, identified apparent exploitation attempts after a proof-of-concept was published online. The firm’s founder, security researcher Ryan Dewhurst, said requests matching the exploit had been detected by one of its NetScaler sensors.
“On 3 September, one of our NetScaler sensors received requests matching the PoC from three distinct source IPs, geolocated to Australia, the United States and Germany,” Mr Dewhurst said.
He added: “Our current assessment is that this provides evidence of exploitation attempts, but it does not confirm successful compromise of real-world systems.”
The Centre for Cybersecurity Belgium, the country’s national cybersecurity coordination centre, separately warned of attempts to exploit the vulnerability and urged organisations to prioritise updates for affected Citrix NetScaler appliances.
Citrix NetScaler vulnerability prompts patching warning
Citrix addressed CVE-2026-19490 in August and advised customers to consult its security bulletin, establish whether their systems were affected and install the recommended firmware builds as soon as possible.
The company did not identify the vulnerability as actively exploited in its August 19 advisory. The subsequent activity reported by Previdian followed the release of the publicly available proof-of-concept.
Internet threat-monitoring organisation Shadowserver is tracking more than 22,000 NetScaler ADC appliances and almost 1,700 Gateway instances exposed online. It is not known how many of those systems are honeypots, have the vulnerable configuration or have already been patched.
The warning comes after two other Citrix NetScaler vulnerabilities, CVE-2026-3055 and CVE-2026-4368, were targeted shortly after Citrix urged administrators to update their systems in March.
The United States Cybersecurity and Infrastructure Security Agency added CVE-2026-3055 to its catalogue of known exploited vulnerabilities the following week and gave federal agencies three days to secure affected Citrix appliances.
Since November 2021, CISA has identified 23 Citrix vulnerabilities as having been exploited in the wild, including six that have also been used by ransomware groups.
