Vulnerability intelligence company Previdian reported on Thursday that its sensors detected exploitation attempts against CVE-2026-19490, a critical-severity authentication bypass in Citrix NetScaler ADC and Gateway appliances. The flaw allows unprivileged attackers to bypass authentication remotely when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the firmware version and whether SAML Action is configured.
Previdian founder Ryan Dewhurst told BleepingComputer that on 3 September, one of the company's NetScaler sensors received requests matching a published proof-of-concept exploit from three distinct source IPs geolocated to Australia, the United States, and Germany. Dewhurst said the evidence points to exploitation attempts but does not confirm successful compromise of real-world systems.
The Centre for Cybersecurity Belgium (NCC-BE) also issued a warning on Friday about exploitation attempts targeting CVE-2026-19490, urging administrators to prioritise patching all vulnerable NetScaler appliances.
Citrix addressed the vulnerability in a security bulletin on 19 August and urged customers to review whether their deployments are affected and upgrade to recommended builds as soon as possible. Shadowserver, an internet threat monitoring organisation, tracks over 22,000 NetScaler ADC appliances and nearly 1,700 Gateway instances exposed online, though it is not known how many of these remain vulnerable.
Organisations using Citrix NetScaler for remote access or authentication are strongly advised to apply the available patches immediately.