Hackers Target Citrix NetScaler Flaw on 22,000 Servers

Security researchers say hackers have begun actively exploiting a critical authentication-bypass flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, just weeks after Citrix shipped a patch for the bug.
The flaw, tracked as CVE-2026-19490, carries a CVSS score of 9.3 out of 10. It lets an unauthenticated attacker bypass login controls on NetScaler appliances configured as a VPN gateway, ICA proxy, CVPN, RDP proxy, or AAA virtual server. Citrix classifies it as an authentication bypass via an alternate path: attackers reach a separate authentication route that skips the checks the normal login path enforces.
Citrix disclosed the bug and released fixes on August 19, 2026, urging customers to upgrade to NetScaler ADC and Gateway 14.1-73.32, 13.1-63.21, or later. No exploitation was reported for weeks. That changed in early September, after proof-of-concept exploit code for the flaw became publicly available.
Security firm Previdian says its NetScaler sensor network first caught exploitation attempts on September 3. Researcher Ryan Dewhurst reported that sensors received requests matching the public exploit from multiple source IP addresses — Previdian's own writeup cites three, geolocated to Australia, the United States, and Germany, while a separate account of the same monitoring effort cites six IPs spanning Australia, Germany, Japan, and the U.S. Previdian says it has not yet confirmed any successful compromise of a real-world system, only scanning and exploitation attempts.
The exposed attack surface is large. Internet-scanning service Shadowserver counts roughly 22,000 NetScaler ADC appliances and nearly 1,700 NetScaler Gateway instances still reachable from the public internet, though it cautions that figure includes honeypots and devices that may already be patched or safely configured.
Why it matters: NetScaler gateways sit at the edge of corporate networks, often providing VPN access into internal systems, which makes them a favorite target for ransomware crews and state-linked hacking groups once a working exploit spreads. Citrix products have a history of being exploited within days of a patch release. Security teams running NetScaler ADC or Gateway should confirm they are on a patched build — 14.1-73.32, 13.1-63.21, or later — and check logs for the anomalous authentication traffic researchers have described, rather than waiting for a wave of confirmed breaches to act.
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- US-China Trade Truce Extended to Jan. 10 as Xi Visits
- Amoeba Breeds at 63°C, Past the 60°C Limit for Complex Life
- 996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
- Oracle Invokes Force Majeure on 2.45GW Stargate Data Center
- Diller Drops $18B MGM Bid; Stock Falls 9.5% to February Levels
- Taylor Swift Adds 4 Songs to ‘Showgirl’ in Sept. 25 Encore
- Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
- Rivian Recalls 98,828 EVs Over Rearview Camera Fault
Comments
No comments yet. Be the first.