[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGZRBAhV3cdMKLpJp6qzJ4lLBUNMcYMzdrWiFmUTIFd4":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"df004bfb-5986-4065-9676-ec02a9f93598","Critical Citrix NetScaler auth bypass now leveraged in attacks","critical-citrix-netscaler-auth-bypass-now-leveraged-in-attacks-7483ae","Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]","Attackers have begun actively exploiting a critical authentication bypass vulnerability (CVE-2026-19490) in Citrix NetScaler appliances. The flaw allows unprivileged actors to bypass authentication remotely under specific configuration conditions. Security researchers and national cybersecurity centers are urging immediate patching due to evidence of exploitation attempts originating from Australia, the US, and Germany.","Attackers exploit critical Citrix NetScaler auth bypass flaw CVE-2026-19490 in the wild.","Critical Citrix NetScaler auth bypass now leveraged in attacks By Sergiu Gatlan September 4, 2026 11:25 AM 0 Attackers have begun targeting a critical-severity Citrix NetScaler flaw in the wild, according to vulnerability intelligence company Previdian. Tracked as CVE-2026-19490, this security flaw can allow unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured. \"We strongly recommend that customers review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,\" Citrix warned in mid-August when it addressed the flaw and urged admins to patch it as soon as possible. While the company has yet to flag the vulnerability as actively exploited in its August 19 security advisory, Previdian founder and security researcher Ryan Dewhurst told BleepingComputer on Thursday that attackers have begun targeting CVE-2026-19490 in the wild after a \"credible\" proof-of-concept exploit was published online. \"On 3 September, one of our NetScaler sensors received requests matching the PoC from three distinct source IPs, geolocated to Australia, the United States and Germany,\" Dewhurst told BleepingComputer. \"Our current assessment is that this provides evidence of exploitation attempts, but it does not confirm successful compromise of real-world systems.\" The Centre for Cybersecurity Belgium, the country's National Cybersecurity Coordination Centre for Belgium (NCC-BE), also warned on Friday of exploitation attempts targeting the CVE-2026-19490 vulnerability and urged admins to prioritize patching all vulnerable Citrix NetScaler appliances on their organizations' networks. Although Internet threat watchdog Shadowserver tracks over 22,000 NetScaler ADC appliances and nearly 1,700 Gateway instances exposed online, there is no information on how many are honeypots, have vulnerable configurations, or have already been patched against CVE-2026-19490 attacks. Citrix urged admins to patch two other NetScaler flaws (CVE-2026-3055 and CVE-2026-4368) in March, just days before threat actors began exploiting them in attacks. The Cybersecurity and Infrastructure Security Agency (CISA) added the CVE-2026-3055 flaw to its catalog of actively exploited vulnerabilities one week later and ordered federal agencies to patch vulnerable Citrix appliances within three days. Since November 2021, the U.S. cybersecurity agency has tagged 23 Citrix vulnerabilities as exploited in the wild, six of which have also been abused by ransomware gangs. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: CISA orders feds to patch Citrix NetScaler RCE flaw by SaturdayCitrix urges admins to patch new NetScaler flaws as soon as possibleHackers leverage new Microsoft SharePoint exploit in attacksHackers exploit critical JFrog Artifactory flaw to forge admin tokensHackers target WordPress sites in miniOrange auth bypass attacks","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-target-critical-citrix-netscaler-auth-bypass-in-attacks\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F09\u002F04\u002FCitrix-headpic.jpg","2026-09-04T15:25:59+00:00","2026-09-04T16:00:27.409378+00:00",9,[18,21,24,27,29,31],{"name":19,"type":20},"NetScaler","product",{"name":22,"type":23},"Citrix","vendor",{"name":25,"type":26},"SSL VPN","technology",{"name":28,"type":26},"ICA Proxy",{"name":30,"type":26},"CVPN",{"name":32,"type":26},"RDP Proxy","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":33,"icon":35,"name":36,"slug":37},null,"Vulnerabilities","vulnerabilities",[39,44,46],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":45},{"id":33,"icon":35,"name":36,"slug":37},{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[52],{"type":53,"value":54,"context":55},"cve","CVE-2026-19490","Critical Citrix NetScaler authentication bypass vulnerability"]