ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Cybersecurity

Attackers target Citrix NetScaler auth bypass

Previdian said attackers had started using a Citrix NetScaler authentication bypass in the wild, while Citrix, Belgium’s cybersecurity centre and CISA repeated calls for administrators to patch affected systems.

BleepingComputer

Previdian said attackers had started targeting CVE-2026-19490 in live attacks. Citrix said the flaw could let remote, unprivileged actors get around authentication when NetScaler appliances were configured in certain AAA or Gateway roles, depending on firmware and SAML Action settings.

Citrix told customers in mid-August to review the security bulletin and upgrade affected systems quickly. In its August 19 advisory, it had not marked the issue as actively exploited.

Ryan Dewhurst, Previdian’s founder and a security researcher, told BleepingComputer that a credible proof of concept had appeared online. He said one of the company’s NetScaler sensors recorded matching requests on 3 September from three source IP addresses associated with Australia, the United States and Germany, but he said that did not show real-world compromise.

The Centre for Cybersecurity Belgium, also known as NCC-BE, warned on Friday about exploitation attempts and told administrators to patch vulnerable Citrix NetScaler appliances on their networks. Shadowserver said it monitored more than 22,000 NetScaler ADC appliances and nearly 1,700 Gateway instances exposed online, but said it could not tell how many were honeypots, still vulnerable or already patched.

Citrix had urged admins in March to patch CVE-2026-3055 and CVE-2026-4368, and threat actors began using them a few days later. CISA added CVE-2026-3055 to its list of actively exploited vulnerabilities one week later and ordered federal agencies to patch vulnerable Citrix appliances within three days. Since November 2021, CISA has tagged 23 Citrix vulnerabilities as exploited in the wild, and six of those were also abused by ransomware gangs.

Named in this story

People

Ryan Dewhurst
told BleepingComputer that sensor traffic matched a proof of concept

Companies

Citrix
warned customers to review the bulletin and patch affected systems
Previdian
said attackers had begun targeting the flaw in the wild

Organisations

Centre for Cybersecurity Belgium
warned of exploitation attempts and urged patching
Shadowserver
tracked exposed NetScaler appliances online

Governments and agencies

Cybersecurity and Infrastructure Security Agency
later added another Citrix flaw to its actively exploited catalogue

Products and systems

NetScaler ADC
one of the affected Citrix appliance lines discussed
NetScaler Gateway
another affected Citrix appliance line discussed

Places

Australia
one of the geolocations for the sensor requests
the United States
one of the geolocations for the sensor requests
Germany
one of the geolocations for the sensor requests

How the source tells it

The piece was mostly straight security reporting, but it used urgent active-exploitation language and ended with a promotional report plug.

  • alarm and urgency critical-severity framing, active-exploitation wording and repeated patch-now advice
  • vendor boosterism the closing shifts from the incident into marketing language for a report and a download prompt