Attackers are actively targeting CVE-2026-19490, a critical Citrix NetScaler authentication bypass flaw, after a credible proof-of-concept exploit was published online. Citrix and Belgium’s NCC-BE have urged administrators to patch vulnerable NetScaler ADC and NetScaler Gateway appliances immediately, as evidence points to exploitation attempts but not yet confirmed compromise. #CVE-2026-19490 #Citrix #NetScaler #NCC-BE
Keypoints
- CVE-2026-19490 allows remote authentication bypass on certain Citrix NetScaler configurations.
- Previdian observed requests matching a public PoC from multiple source IPs.
- NCC-BE warned of exploitation attempts and urged immediate patching.
- Shadowserver reports over 22,000 exposed NetScaler ADC appliances and nearly 1,700 Gateway instances online.
- Citrix and CISA have repeatedly flagged NetScaler flaws as actively exploited in the wild.