Critical Citrix NetScaler auth bypass now leveraged in attacks
Reported exploitedCitrix NetScaler ADCNetScaler GatewayOur summary
Security researchers at Previdian have observed active exploitation attempts against CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and Gateway appliances. This flaw enables unprivileged attackers to remotely circumvent authentication controls on devices configured as AAA virtual servers or Gateways (including SSL VPN and RDP proxies). While Citrix issued a patch in mid-August, recent data indicates that adversaries began targeting this weakness following the publication of a proof-of-concept exploit. Belgian cyber authorities have also warned organizations to prioritize upgrading vulnerable NetScaler instances to the recommended builds.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.