Critical NetScaler Vulnerability Exploited in Attacks
Critical NetScaler vulnerability CVE-2026-19490 exploited in the wild since September 3.
Summary
CISA has warned that threat actors are actively exploiting a critical NetScaler vulnerability, CVE-2026-19490, which has a CVSS score of 9.3. The flaw impacts NetScaler ADC and Gateway appliances configured as gateways or AAA virtual servers. Citrix released a patch on August 19, and the vulnerability has been exploited in the wild since at least September 3, prompting CISA to add it to its Known Exploited Vulnerabilities catalog.
Full text
The US Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday warned that threat actors have been exploiting a critical-severity NetScaler vulnerability in attacks. Tracked as CVE-2026-19490 (CVSS score of 9.3), the security defect impacts all NetScaler ADC and NetScaler Gateway appliances configured as a gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server. Citrix patched the flaw on August 19, when cybersecurity firm Rapid7 warned that it could be exploited remotely without authentication. Rapid7 also said it was expecting threat actors to start exploiting the bug shortly, given the nature of NetScaler deployments within enterprise environments. “Organizations should prioritize patching affected systems on an emergency basis, since Citrix products are high-value targets that tend to quickly see exploitation in the wild,” the company said. On Wednesday, CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, in line with BOD 26-04’s requirements.Advertisement. Scroll to continue reading. While the cybersecurity agency has not provided details on the observed exploitation attempts, its alert comes roughly a week after Previdian founder and former WatchTowr head of threat intelligence Ryan Dewhurst warned that hackers started exploiting the vulnerability. “An unverified but credible PoC appeared yesterday. Today, 3 IPs across 3 countries sent matching requests to our sensor,” Dewhurst said. CVE-2026-19490’s exploitation has been ongoing since at least September 3, one day after an exploit targeting it was published on GitHub, data from Previdian shows. Related: Organizations Warned of Cisco Secure FMC Exploitation Related: New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks Related: N-able Patches Critical Zero-Day in N-central Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Android’s September 2026 Updates Patch 180 VulnerabilitiesChipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security AdvisoriesFortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome ExtensionICS Patch Tuesday: Schneider Electric, Siemens Fix Critical FlawsIvanti Patches Critical Flaws Across Enterprise Security ProductsChrome 153 Patches Seventh Zero-Day of 2026Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-DaysAdobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day Latest News Deceptive Android Apps Exploit Google Play Early Access to Evade ReviewsWebinar Today: Keep Pace With AI – A New Operating Model for Endpoint RemediationWidened Scan Turns Up Fourth Rogue Claude Cyber Incident4.1 Million Impacted by AdaptHealth Data BreachOrganizations Warned of Cisco Secure FMC ExploitationNew ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft DefenderFortinet Code Execution Flaw Exploited in PivotC2 RAT AttacksHelmGuard Raises $7.3 Million for Agentic GRC and Security Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveAmazon has elected Kevin Mandia to its Board of Directors.Gigamon has named Grant Yacomeni as Chief Information Security Officer.SSH Communications Security has appointed Lars Bell as Chief Executive Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-19490