Critical Citrix NetScaler auth bypass now leveraged in attacks
What happened
Previdian reported that attackers began targeting CVE-2026-19490, a critical Citrix NetScaler authentication bypass, after a proof-of-concept exploit was published. The company detected requests matching the exploit from three distinct source IPs on September 3, though it noted this evidence does not confirm successful compromise of real-world systems.
Why it ranks #1
Previdian detected requests matching the proof-of-concept exploit for CVE-2026-19490, a critical Citrix NetScaler authentication bypass, from three distinct source IPs on September 3, though the company noted this evidence does not confirm successful compromise of real-world systems.
Who should care
Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams
What to do
Patch all vulnerable Citrix NetScaler appliances to mitigate exploitation attempts targeting CVE-2026-19490.
- Impact
- high
- Urgency
- immediate
- Confidence
- high
- Scope
- product
- Status
- actively exploited