Damus
Ox HaK profile picture
Ox HaK
@oxhak
CISA has warned that threat actors are exploiting CVE-2026-19490, a critical authentication-bypass vulnerability in Citrix NetScaler. The flaw has a CVSS score of 9.3 and affects NetScaler ADC and NetScaler Gateway appliances configured as a gateway—such as SSL VPN, ICA Proxy, CVPN or RDP Proxy—or as an AAA virtual server. Citrix released a patch on August 19 after Rapid7 said the issue could be exploited remotely without authentication.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on Wednesday, requiring US federal agencies to remediate it within three days. Independent data from Previdian indicates exploitation has continued since at least September 3, one day after an exploit was published on GitHub. The incident matters because NetScaler systems are widely deployed at enterprise network perimeters and are considered high-value targets.

https://www.securityweek.com/critical-netscaler-vulnerability-exploited-in-attacks/