Active Exploitation of Critical NetScaler Flaw

CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities list, warning NetScaler appliances are being exploited and directing federal agencies to patch within three days.

The U.S. Cybersecurity and Infrastructure Security Agency announced that threat actors are actively exploiting a critical Citrix NetScaler vulnerability tracked as CVE-2026-19490. CISA added the flaw to its Known Exploited Vulnerabilities catalog and directed federal civilian agencies to remediate affected systems within three days under BOD 26-04.

CVE-2026-19490 has a CVSS score of 9.3. It affects all NetScaler ADC and NetScaler Gateway appliances when they are configured as a gateway (including SSL VPN, ICA Proxy, CVPN and RDP Proxy) or as an AAA virtual server. Citrix released a patch on Aug. 19 after researchers reported the flaw could be exploited remotely without authentication.

Proof-of-concept exploit code was posted publicly on Sept. 2. Previdian telemetry indicates exploitation activity began at least by Sept. 3, one day after the public exploit appeared. Previdian founder Ryan Dewhurst reported that an unverified proof-of-concept appeared followed by matching requests from three IP addresses across three countries to the company’s sensor. CISA’s alert did not include technical details of observed attacks.

Security firm Rapid7 urged organizations to prioritize patching affected NetScaler systems on an emergency basis, noting that NetScaler products are high-value targets that often see rapid exploitation in the wild.

Administrators should apply Citrix’s August update to vulnerable ADC and Gateway appliances. Teams that cannot immediately install the patch are advised to isolate or restrict access to affected appliances until updates are applied. Network defenders should monitor gateway and AAA service logs for anomalous requests and unusual connection patterns consistent with remote probing or exploitation attempts.

Other recent incidents have shown published proof-of-concept code can precede observed exploitation of remote-access appliances. CVE-2026-19490 is the latest vulnerability in which public exploit code was followed quickly by active attacks.

Articles by this author