Download Privacy Needle App

Type to search

Cybersecurity

CISA Warns of Active Exploitation of Critical NetScaler Vulnerability

Share

The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that threat actors are actively exploiting a critical authentication bypass vulnerability in NetScaler appliances.

The flaw, tracked as CVE-2026-19490, has a CVSS score of 9.3, reflecting its high severity. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalogue on Wednesday, urging federal agencies to apply patches within three days in accordance with binding operational directive BOD 26-04.

Affected NetScaler Systems

The security defect impacts all NetScaler ADC and NetScaler Gateway appliances configured as a gateway—including SSL VPN, ICA Proxy, CVPN, and RDP Proxy—or as an AAA (Authentication, Authorization, and Accounting) virtual server.

Citrix released a patch for the vulnerability on 19 August. Security researchers at Rapid7 had previously warned that the flaw could be exploited remotely without requiring authentication, noting that NetScaler deployments are high-value targets for attackers.

Ongoing Exploitation

Evidence suggests that exploitation has been occurring in the wild since at least 3 September. This follows the publication of an exploit targeting the flaw on GitHub on 2 September.

Ryan Dewhurst, founder of Previdian and former head of threat intelligence at WatchTowr, reported that unverified but credible proof-of-concept (PoC) code appeared online shortly before matching malicious requests were detected across multiple countries. Data from Previdian indicates that the exploitation attempts have been ongoing for several days.

Organisations using affected NetScaler products are advised to prioritise emergency patching to mitigate the risk of unauthorised access.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.