Attackers have begun targeting a critical-severity flaw in Citrix NetScaler appliances in live attacks, according to vulnerability intelligence firm Previdian. The issue, tracked as CVE-2026-19490, allows unprivileged threat actors to remotely bypass authentication when the appliance runs as an AAA virtual server or as a Gateway, including for SSL VPN, ICA Proxy, CVPN, and RDP Proxy. Whether a deployment is vulnerable depends on the NetScaler firmware version and the configuration of SAML Action. Citrix addressed the flaw in mid-August and urged administrators to review its official security bulletin and upgrade affected appliances to recommended builds as soon as possible.

Previdian founder and researcher Ryan Dewhurst reported that a "credible" proof-of-concept exploit had been published online, and that the firm’s sensors began receiving matching requests on September 3. Those requests came from three distinct source IP addresses geolocated to Australia, the United States, and Germany. Dewhurst said the activity provides evidence of exploitation attempts, but does not confirm that any real-world systems were successfully compromised.

The Centre for Cybersecurity Belgium, which serves as the country’s National Cybersecurity Coordination Centre, also issued a warning on Friday about exploitation attempts targeting CVE-2026-19490. The agency urged administrators to prioritize patching all vulnerable Citrix NetScaler appliances on their networks. Citrix has not yet flagged the vulnerability as actively exploited in its August 19 security advisory.

Internet threat monitor Shadowserver tracks more than 22,000 NetScaler ADC appliances and nearly 1,700 Gateway instances exposed online. However, there is no available information on how many of those systems are honeypots, how many run vulnerable configurations, or how many have already been patched against this specific flaw.

This is not the first time Citrix NetScaler customers have faced a fast-moving threat window. In March, Citrix urged administrators to patch two other NetScaler flaws, CVE-2026-3055 and CVE-2026-4368, just days before attackers began exploiting them in the wild. The Cybersecurity and Infrastructure Security Agency added CVE-2026-3055 to its catalog of actively exploited vulnerabilities one week later and ordered federal agencies to patch affected Citrix appliances within three days.

Since November 2021, CISA has tagged 23 Citrix vulnerabilities as exploited in the wild, and six of those have also been abused by ransomware gangs. The repeated pattern highlights the broader challenge of securing these edge devices, particularly in U.S. government and enterprise environments where they serve as critical access points. The Blue Report 2026, which measures defenses across 338 million simulations in customer production environments, notes that overall prevention scores can hide what occurs after initial access, as prevention drops sharply once attackers use valid credentials.

More cybersecurity news from TechManNews.