CISA Warns of Active Exploitation of Critical NetScaler Vulnerability
Share
The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that threat actors are actively exploiting a critical authentication bypass vulnerability in NetScaler appliances.
The flaw, tracked as CVE-2026-19490, has a CVSS score of 9.3, reflecting its high severity. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalogue on Wednesday, urging federal agencies to apply patches within three days in accordance with binding operational directive BOD 26-04.
Affected NetScaler Systems
The security defect impacts all NetScaler ADC and NetScaler Gateway appliances configured as a gateway—including SSL VPN, ICA Proxy, CVPN, and RDP Proxy—or as an AAA (Authentication, Authorization, and Accounting) virtual server.
Citrix released a patch for the vulnerability on 19 August. Security researchers at Rapid7 had previously warned that the flaw could be exploited remotely without requiring authentication, noting that NetScaler deployments are high-value targets for attackers.
Ongoing Exploitation
Evidence suggests that exploitation has been occurring in the wild since at least 3 September. This follows the publication of an exploit targeting the flaw on GitHub on 2 September.
Ryan Dewhurst, founder of Previdian and former head of threat intelligence at WatchTowr, reported that unverified but credible proof-of-concept (PoC) code appeared online shortly before matching malicious requests were detected across multiple countries. Data from Previdian indicates that the exploitation attempts have been ongoing for several days.
Organisations using affected NetScaler products are advised to prioritise emergency patching to mitigate the risk of unauthorised access.




Leave a Reply