Exploited in the wild Citrix NetScaler ADC auth-bypass NetScaler Gateway Citrix zero-day
Critical Citrix NetScaler auth bypass now leveraged in attacks
CVE Tools coverage
Security researchers at Previdian have observed active exploitation attempts against CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and Gateway appliances. This flaw enables unprivileged attackers to remotely circumvent authentication controls on devices configured as AAA virtual servers or Gateways (including SSL VPN and RDP proxies). While Citrix issued a patch in mid-August, recent data indicates that adversaries began targeting this weakness following the publication of a proof-of-concept exploit. Belgian cyber authorities have also warned organizations to prioritize upgrading vulnerable NetScaler instances to the recommended builds.