Cyber Security News

CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks

CISA added a critical Citrix NetScaler authentication bypass flaw (CVE-2026-19490) to its Known Exploited Vulnerabilities catalog after observing in-the-wild attacks targeting the issue. Federal civilian agencies must apply vendor mitigations by September 12, 2026.

CVE-2026-19490 affects Citrix NetScaler ADC and NetScaler Gateway appliances configured as an Authentication, Authorization and Auditing virtual server or as a Gateway service. This includes deployments supporting SSL VPN, ICA Proxy, CVPN, and RDP Proxy functions.

The flaw is categorized as CWE-288, Authentication Bypass Using an Alternate Path or Channel. It could allow a remote, unauthenticated attacker to bypass login protections and access functionality that normally requires valid credentials.

Because NetScaler appliances are commonly deployed at the edge of corporate networks to provide remote access, successful exploitation could expose sensitive applications and internal services.

Citrix released security updates for the vulnerability on August 19, 2026. Exploitation activity was subsequently detected after a credible proof-of-concept exploit became publicly available.

Citrix NetScaler Authentication Bypass Vulnerability Exploited

Security researchers observed attack requests targeting honeypot systems beginning on September 3, with 56 attempts logged through September 8. Available reporting indicates attempted exploitation but does not independently confirm that attackers successfully compromised production environments using the flaw.

The issue affects NetScaler ADC and NetScaler Gateway version 14.1 releases before 14.1-73.32, as well as version 13.1 releases before 13.1-63.21.

Citrix NetScaler ADC FIPS builds before 14.1-73.32, and NetScaler ADC FIPS and NDcPP builds before 13.1-37.277 are also affected. Organizations should upgrade to the corresponding fixed builds or later releases.

Newer vulnerable installations require specific configuration conditions, including use as a SAML identity provider. Earlier builds can be affected when configured as a Gateway or AAA virtual server.

Administrators should therefore identify all internet-facing NetScaler instances, confirm their firmware version, and review AAA, Gateway, VPN, and SAML settings.

CISA’s inclusion of CVE-2026-19490 in the KEV catalog means agencies must prioritize remediation under Binding Operational Directive 26-04. The agency also requires forensic triage for affected assets, emphasizing that patching alone may not be sufficient when exposure or suspicious activity is identified.

Security teams should examine appliance logs for anomalous authentication events, unexpected requests, configuration modifications, new administrator sessions, and unusual outbound connections.

Organizations should isolate potentially compromised appliances, preserve evidence, rotate relevant credentials, and assess downstream systems accessible through the affected gateway.

No ransomware use has been confirmed for CVE-2026-19490 so far. However, the combination of public exploit code, internet-facing VPN infrastructure, and observed exploitation attempts makes patching an urgent priority for all organizations running affected Citrix NetScaler deployments.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago