Exploitation attempts against the Citrix NetScaler auth bypass vulnerability CVE-2026-19490 have begun in the wild, with attackers probing appliances just days after a credible proof-of-concept exploit appeared online. The flaw carries a CVSS v4.0 score of 9.3, according to Field Effect, placing it firmly in critical territory.
The vulnerability, classified as CWE-288: Authentication Bypass Using an Alternate Path by Penligent, allows unprivileged threat actors to bypass authentication remotely. It affects NetScaler appliances configured as an AAA virtual server or as a Gateway (covering SSL VPN, ICA Proxy, CVPN, and RDP Proxy configurations) depending on the firmware version and whether SAML Action is configured.
Where the Citrix NetScaler Auth Bypass Was First Spotted
Previdian founder and security researcher Ryan Dewhurst told BleepingComputer on Thursday that the exploitation activity followed the publication of a ‘credible’ proof-of-concept. ‘On 3 September, one of our NetScaler sensors received requests matching the PoC from three distinct source IPs, geolocated to Australia, the United States and Germany,’ Dewhurst said. He was careful not to overstate the significance: ‘Our current assessment is that this provides evidence of exploitation attempts, but it does not confirm successful compromise of real-world systems.’
The Centre for Cybersecurity Belgium, the country’s National Cybersecurity Coordination Centre (NCC-BE), issued its own warning on Friday, urging administrators to prioritise patching all vulnerable Citrix NetScaler appliances on their networks. Citrix itself had addressed the flaw in mid-August, warning customers to ‘review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible.’ As of the company’s 19 August security advisory, it had not yet flagged CVE-2026-19490 as actively exploited.
Which Versions Are Vulnerable and What Admins Should Patch
According to Rapid7, the affected builds include NetScaler ADC and NetScaler Gateway 14.1 versions prior to 14.1-73.32, as well as 13.1 versions prior to 13.1-63.21. Administrators running either branch should treat patching as a priority, not a scheduled maintenance item.
The urgency is reinforced by the scale of exposure. Internet threat watchdog Shadowserver tracks over 22,000 NetScaler ADC appliances and nearly 1,700 Gateway instances exposed online, though there is no breakdown of how many are honeypots, carry vulnerable configurations, or have already been patched against CVE-2026-19490 attacks.
A Familiar Pattern for Citrix Vulnerabilities
This is not the first time a NetScaler flaw has moved rapidly from advisory to active exploitation, and the pattern is becoming predictable in an uncomfortable way. In March, Citrix urged admins to patch two other NetScaler flaws, CVE-2026-3055 and CVE-2026-4368, just days before threat actors began exploiting them in attacks. The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-3055 to its catalogue of actively exploited vulnerabilities one week later and ordered federal agencies to patch within three days.
The broader history is grimmer still. Since November 2021, CISA has tagged 23 Citrix vulnerabilities as exploited in the wild. Six of those have also been abused by ransomware gangs, a reminder that authentication bypass flaws in network edge infrastructure tend to be particularly attractive for groups that need persistent, stealthy access before deploying a payload.
The Citrix NetScaler auth bypass tracked as CVE-2026-19490 fits squarely into that pattern: a critical-severity flaw on internet-facing appliances, a proof-of-concept now circulating, and early sensor hits from multiple continents. CISA has not yet added it to its actively exploited catalogue, but given the March precedent, that status could change quickly. Administrators who have not yet applied the recommended firmware builds should do so before that update arrives.

