Cybersecurity
Attackers target Citrix NetScaler auth bypass
Previdian said attackers had started using a Citrix NetScaler authentication bypass in the wild, while Citrix, Belgium’s cybersecurity centre and CISA repeated calls for administrators to patch affected systems.
- Previdian said attackers had begun targeting CVE-2026-19490 in the wild.
- Citrix said the flaw could allow remote, unprivileged attackers to bypass authentication on certain NetScaler setups.
- Ryan Dewhurst said one of Previdian’s sensors saw requests matching a published proof of concept from Australia, the United States and Germany on 3 September, but he said that did not prove compromise.
- The Centre for Cybersecurity Belgium warned of exploitation attempts, and Shadowserver said it tracked more than 22,000 exposed NetScaler ADC appliances and nearly 1,700 Gateway instances online.
Previdian said attackers had started targeting CVE-2026-19490 in live attacks. Citrix said the flaw could let remote, unprivileged actors get around authentication when NetScaler appliances were configured in certain AAA or Gateway roles, depending on firmware and SAML Action settings.
Citrix told customers in mid-August to review the security bulletin and upgrade affected systems quickly. In its August 19 advisory, it had not marked the issue as actively exploited.
Ryan Dewhurst, Previdian’s founder and a security researcher, told BleepingComputer that a credible proof of concept had appeared online. He said one of the company’s NetScaler sensors recorded matching requests on 3 September from three source IP addresses associated with Australia, the United States and Germany, but he said that did not show real-world compromise.
The Centre for Cybersecurity Belgium, also known as NCC-BE, warned on Friday about exploitation attempts and told administrators to patch vulnerable Citrix NetScaler appliances on their networks. Shadowserver said it monitored more than 22,000 NetScaler ADC appliances and nearly 1,700 Gateway instances exposed online, but said it could not tell how many were honeypots, still vulnerable or already patched.
Citrix had urged admins in March to patch CVE-2026-3055 and CVE-2026-4368, and threat actors began using them a few days later. CISA added CVE-2026-3055 to its list of actively exploited vulnerabilities one week later and ordered federal agencies to patch vulnerable Citrix appliances within three days. Since November 2021, CISA has tagged 23 Citrix vulnerabilities as exploited in the wild, and six of those were also abused by ransomware gangs.
Named in this story
People
- Ryan Dewhurst
- told BleepingComputer that sensor traffic matched a proof of concept
Companies
- Citrix
- warned customers to review the bulletin and patch affected systems
- Previdian
- said attackers had begun targeting the flaw in the wild
Organisations
- Centre for Cybersecurity Belgium
- warned of exploitation attempts and urged patching
- Shadowserver
- tracked exposed NetScaler appliances online
Governments and agencies
- Cybersecurity and Infrastructure Security Agency
- later added another Citrix flaw to its actively exploited catalogue
Products and systems
- NetScaler ADC
- one of the affected Citrix appliance lines discussed
- NetScaler Gateway
- another affected Citrix appliance line discussed
Places
- Australia
- one of the geolocations for the sensor requests
- the United States
- one of the geolocations for the sensor requests
- Germany
- one of the geolocations for the sensor requests
How the source tells it
The piece was mostly straight security reporting, but it used urgent active-exploitation language and ended with a promotional report plug.
- alarm and urgency critical-severity framing, active-exploitation wording and repeated patch-now advice
- vendor boosterism the closing shifts from the incident into marketing language for a report and a download prompt