Exploitation of Citrix NetScaler Authentication Bypass Vulnerability CVE-2026-19490

Exploitation of Citrix NetScaler Authentication Bypass Vulnerability CVE-2026-19490

First seen 4 Sep 2026, 21:06 UTC ThecyberexpressFieldeffectwww.bleepingcomputer.com 72.9

Article Content

Browse articles
ThreatCluster

On September 4, 2026, it was reported that threat actors are actively targeting a critical authentication bypass vulnerability in Citrix NetScaler, tracked as CVE-2026-19490. This flaw allows unauthenticated attackers to bypass authentication controls on affected NetScaler ADC and Gateway deployments, potentially granting access to sensitive applications. The vulnerability was publicly disclosed on August 19, 2026, and a proof-of-concept exploit was released on September 3, 2026. Citrix has urged organizations to apply security updates and monitor for unauthorized access. The CVE has a CVSS v4.0 score of 9.3, indicating its critical severity. Organizations using NetScaler products are advised to assess their configurations and apply patches immediately. The Australian Cyber Security Centre has issued warnings, although no specific sectors are currently reported as targeted.

Key Points: • CVE-2026-19490 allows unauthenticated access to Citrix NetScaler systems. • Public proof-of-concept exploit code was released on September 3, 2026. • Citrix released patches for the vulnerabilities on August 19, 2026.

Ask AI about this cluster

Timeline

2026-03-23
CVE-2026-3055 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-23
CVE-2026-4368 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-19
CVE-2026-19490 published
Citrix disclosed a critical authentication bypass vulnerability affecting NetScaler products.
Fieldeffect
2026-08-19
CVE-2026-19489 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-03
Public PoC released
A proof-of-concept exploit for CVE-2026-19490 was published, enabling exploitation attempts.
BleepingComputer
2026-09-04
Active exploitation reported
Threat actors began targeting CVE-2026-19490 in the wild following the PoC release.
BleepingComputer
2026-09-04
ACSC issues warning
The Australian Cyber Security Centre advised organizations to patch and monitor their Citrix systems.
Thecyberexpress