Cybersecurity

Hackers Target Citrix NetScaler Flaw on 22,000 Servers

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

Hackers Target Citrix NetScaler Flaw on 22,000 Servers
0 0
XWhatsAppTelegramLinkedIn

Security researchers say hackers have begun actively exploiting a critical authentication-bypass flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, just weeks after Citrix shipped a patch for the bug.

The flaw, tracked as CVE-2026-19490, carries a CVSS score of 9.3 out of 10. It lets an unauthenticated attacker bypass login controls on NetScaler appliances configured as a VPN gateway, ICA proxy, CVPN, RDP proxy, or AAA virtual server. Citrix classifies it as an authentication bypass via an alternate path: attackers reach a separate authentication route that skips the checks the normal login path enforces.

Citrix disclosed the bug and released fixes on August 19, 2026, urging customers to upgrade to NetScaler ADC and Gateway 14.1-73.32, 13.1-63.21, or later. No exploitation was reported for weeks. That changed in early September, after proof-of-concept exploit code for the flaw became publicly available.

Security firm Previdian says its NetScaler sensor network first caught exploitation attempts on September 3. Researcher Ryan Dewhurst reported that sensors received requests matching the public exploit from multiple source IP addresses — Previdian's own writeup cites three, geolocated to Australia, the United States, and Germany, while a separate account of the same monitoring effort cites six IPs spanning Australia, Germany, Japan, and the U.S. Previdian says it has not yet confirmed any successful compromise of a real-world system, only scanning and exploitation attempts.

The exposed attack surface is large. Internet-scanning service Shadowserver counts roughly 22,000 NetScaler ADC appliances and nearly 1,700 NetScaler Gateway instances still reachable from the public internet, though it cautions that figure includes honeypots and devices that may already be patched or safely configured.

Why it matters: NetScaler gateways sit at the edge of corporate networks, often providing VPN access into internal systems, which makes them a favorite target for ransomware crews and state-linked hacking groups once a working exploit spreads. Citrix products have a history of being exploited within days of a patch release. Security teams running NetScaler ADC or Gateway should confirm they are on a patched build — 14.1-73.32, 13.1-63.21, or later — and check logs for the anomalous authentication traffic researchers have described, rather than waiting for a wave of confirmed breaches to act.

Report / request removal

Related

Comments

No comments yet. Be the first.