Critical Citrix NetScaler auth bypass now leveraged in attacks

Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers are actively targeting CVE-2026-19490, a critical Citrix NetScaler authentication bypass flaw, after a credible proof-of-concept exploit was published online. Citrix and Belgium’s NCC-BE have urged administrators to patch vulnerable NetScaler ADC and NetScaler Gateway appliances immediately, as evidence points to exploitation attempts but not yet confirmed compromise. #CVE-2026-19490 #Citrix #NetScaler #NCC-BE

Keypoints

  • CVE-2026-19490 allows remote authentication bypass on certain Citrix NetScaler configurations.
  • Previdian observed requests matching a public PoC from multiple source IPs.
  • NCC-BE warned of exploitation attempts and urged immediate patching.
  • Shadowserver reports over 22,000 exposed NetScaler ADC appliances and nearly 1,700 Gateway instances online.
  • Citrix and CISA have repeatedly flagged NetScaler flaws as actively exploited in the wild.

Read More: https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/