SECURITY researchers warn that a critical authentication bypass flaw in Citrix NetScaler appliances is being exploited in the wild. Tracked as CVE-2026-19490, the vulnerability carries a CVSS score of 9.3 and affects all NetScaler ADC and NetScaler Gateway devices configured as a gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server.
Citrix issued a patch on 19 August after Rapid7 flagged the issue as exploitable remotely without authentication, and Rapid7 later cautioned that threat actors were likely to begin exploiting it given typical NetScaler deployments in large organisations.
Evidence of exploitation emerged publicly in early September. Previdian telemetry shows exploitation activity beginning at least on 3 September, a day after a PoC was published on GitHub. Observations cited by Previdian include multiple requests matching the exploited pattern from three IPs across three countries.
As of CISA’s alert, the attack activity has escalated to a level where CVE-2026-19490 has been added to the Known Exploited Vulnerabilities (KEV) catalog, with federal agencies urged to patch within three days under BOD 26-04. While the alert does not detail individual targets, Citrix products are described as high-value assets that frequently attract rapid exploitation in the wild.
The practical response is straightforward: prioritise emergency patching for affected NetScaler appliances, assess exposure of gateway/AAA virtual servers, and monitor for indicators of compromise related to this vulnerability. The guidance implies rapid remediation to mitigate the risk of remote exploitation by unauthenticated attackers.