Critical NetScaler Vulnerability Exploited in Attacks

MediumSecurityWeek · Ionut Arghire·

At a glance

Severity
Medium
Used in attacks
No flaws named
Reported by
1 outlet

The US Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday warned that threat actors have been exploiting a critical-severity NetScaler vulnerability in attacks.

Tracked as CVE-2026-19490 (CVSS score of 9.3), the security defect impacts all NetScaler ADC and NetScaler Gateway appliances configured as a gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server.

Citrix patched the flaw on August 19, when cybersecurity firm Rapid7 warned that it could be exploited remotely without authentication.

Rapid7 also said it was expecting threat actors to start exploiting the bug shortly, given the nature of NetScaler deployments within enterprise environments.

“Organizations should prioritize patching affected systems on an emergency basis, since Citrix products are high-value targets that tend to quickly see exploitation in the wild,” the company said.

On Wednesday, CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, in line with BOD 26-04’s requirements.

Advertisement. Scroll to continue reading.

While the cybersecurity agency has not provided details on the observed exploitation attempts, its alert comes roughly a week after Previdian founder and former WatchTowr head of threat intelligence Ryan Dewhurst warned that hackers started exploiting the vulnerability.

“An unverified but credible PoC appeared yesterday. Today, 3 IPs across 3 countries sent matching requests to our sensor,” Dewhurst said.

CVE-2026-19490’s exploitation has been ongoing since at least September 3, one day after an exploit targeting it was published on GitHub, data from Previdian shows.

Related: Organizations Warned of Cisco Secure FMC Exploitation

Related: New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

Related: N-able Patches Critical Zero-Day in N-central

Reproduced in full under licence from SecurityWeek. © SecurityWeek. Written by Ionut Arghire.

Coverage

One outlet has carried this so far.

  1. SecurityWeekEstablished SourceFirst reported

    2026-09-10 12:20 UTC

Related stories