Critical NetScaler Vulnerability Exploited in Attacks
Reported exploitedCitrix NetScaler ADCCitrix NetScaler GatewayOur summary
CISA has confirmed that threat actors are actively leveraging a critical authentication bypass flaw in Citrix NetScaler ADC and NetScaler Gateway appliances. Tracked as CVE-2026-19490 with a CVSS score of 9.3, this vulnerability affects devices configured as gateways or AAA virtual servers and allows remote exploitation without prior authentication. Although Citrix released a patch on August 19, CISA added the bug to its Known Exploited Vulnerabilities catalog this week, citing observed attacks since September 3.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.