www.securityweek.com 10 Sept 2026, 12:20 UTC

CISA Warns Attackers Are Exploiting Critical Citrix NetScaler Flaw

CISA Warns Attackers Are Exploiting Critical Citrix NetScaler Flaw
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown

SECURITY researchers warn that a critical authentication bypass flaw in Citrix NetScaler appliances is being exploited in the wild. Tracked as CVE-2026-19490, the vulnerability carries a CVSS score of 9.3 and affects all NetScaler ADC and NetScaler Gateway devices configured as a gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server.

Citrix issued a patch on 19 August after Rapid7 flagged the issue as exploitable remotely without authentication, and Rapid7 later cautioned that threat actors were likely to begin exploiting it given typical NetScaler deployments in large organisations.

Evidence of exploitation emerged publicly in early September. Previdian telemetry shows exploitation activity beginning at least on 3 September, a day after a PoC was published on GitHub. Observations cited by Previdian include multiple requests matching the exploited pattern from three IPs across three countries.

As of CISA’s alert, the attack activity has escalated to a level where CVE-2026-19490 has been added to the Known Exploited Vulnerabilities (KEV) catalog, with federal agencies urged to patch within three days under BOD 26-04. While the alert does not detail individual targets, Citrix products are described as high-value assets that frequently attract rapid exploitation in the wild.

The practical response is straightforward: prioritise emergency patching for affected NetScaler appliances, assess exposure of gateway/AAA virtual servers, and monitor for indicators of compromise related to this vulnerability. The guidance implies rapid remediation to mitigate the risk of remote exploitation by unauthenticated attackers.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline