Attackers begin probing critical Citrix NetScaler authentication bypass
Previdian sensors logged requests matching a public proof-of-concept for CVE-2026-19490, which Citrix patched in August.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
Attackers have started targeting a critical authentication bypass in Citrix NetScaler appliances, according to vulnerability intelligence firm Previdian. The flaw, CVE-2026-19490, lets unprivileged remote attackers bypass authentication when a NetScaler appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN and RDP Proxy modes, depending on firmware version and whether SAML Action is configured. Citrix addressed the issue in mid-August and urged administrators to review its NetScaler ADC and NetScaler Gateway security bulletin and upgrade to the recommended builds as soon as possible. Its August 19 advisory does not yet flag the vulnerability as actively exploited. Previdian founder Ryan Dewhurst told BleepingComputer that exploitation attempts followed the online publication of a proof-of-concept exploit he described as credible. On September 3, one of the firm's NetScaler sensors received requests matching that proof-of-concept from three distinct source IP addresses geolocated to Australia, the United States and Germany. NetScaler appliances sit at the network edge and handle remote access for many enterprises, so an authentication bypass exposes internal resources directly. Organizations that have not yet applied the August fixes should treat this as urgent and check their appliances for signs of probing.
Sources
- BleepingComputerCritical Citrix NetScaler auth bypass now leveraged in attacks