Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Russian drone hits Ukranian security headquarters, Zelensky says

    September 4, 2026

    US court ruling aggravates Brussels’ Google problem – POLITICO

    September 4, 2026

    Investigations launched into polling firm at centre of Reform UK allegations | Reform UK

    September 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Russian drone hits Ukranian security headquarters, Zelensky says
    • US court ruling aggravates Brussels’ Google problem – POLITICO
    • Investigations launched into polling firm at centre of Reform UK allegations | Reform UK
    • Nigel Farage says his aides’ donor comments were ‘loose pub talk’
    • CD sales are making an unexpected comeback amid a retro tech boom
    • Critical Citrix NetScaler auth bypass now leveraged in attacks
    • OpenAI Agents Hack German Website to Share Rule-Breaking Tactics: Report
    • Nigerians die after inhaling toxic fumes during alleged pipeline theft, community group says
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 4
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical Citrix NetScaler auth bypass now leveraged in attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 4, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Attackers have begun targeting a critical-severity Citrix NetScaler flaw in the wild, according to vulnerability intelligence company Previdian.

    Tracked as CVE-2026-19490, this security flaw can allow unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured.

    “We strongly recommend that customers review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,” Citrix warned in mid-August when it addressed the flaw and urged admins to patch it as soon as possible.

    While the company has yet to flag the vulnerability as actively exploited in its August 19 security advisory, Previdian founder and security researcher Ryan Dewhurst told BleepingComputer on Thursday that attackers have begun targeting CVE-2026-19490 in the wild after a “credible” proof-of-concept exploit was published online.

    “On 3 September, one of our NetScaler sensors received requests matching the PoC from three distinct source IPs, geolocated to Australia, the United States and Germany,” Dewhurst told BleepingComputer.

    “Our current assessment is that this provides evidence of exploitation attempts, but it does not confirm successful compromise of real-world systems.”

    CVE-2026-19490 dewhurst

    The Centre for Cybersecurity Belgium, the country’s National Cybersecurity Coordination Centre for Belgium (NCC-BE), also warned on Friday of exploitation attempts targeting the CVE-2026-19490 vulnerability and urged admins to prioritize patching all vulnerable Citrix NetScaler appliances on their organizations’ networks.

    Although Internet threat watchdog Shadowserver tracks over 22,000 NetScaler ADC appliances and nearly 1,700 Gateway instances exposed online, there is no information on how many are honeypots, have vulnerable configurations, or have already been patched against CVE-2026-19490 attacks.

    Citrix urged admins to patch two other NetScaler flaws (CVE-2026-3055 and CVE-2026-4368) in March, just days before threat actors began exploiting them in attacks.

    The Cybersecurity and Infrastructure Security Agency (CISA) added the CVE-2026-3055 flaw to its catalog of actively exploited vulnerabilities one week later and ordered federal agencies to patch vulnerable Citrix appliances within three days.

    Since November 2021, the U.S. cybersecurity agency has tagged 23 Citrix vulnerabilities as exploited in the wild, six of which have also been abused by ransomware gangs.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    attacks auth Bypass Citrix critical leveraged NetScaler
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft says some users can’t open the Teams desktop client

    Sangoma Switchvox Vulnerabilities Exploited in the Wild

    Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

    Google warns of new Chrome zero-day flaw exploited in attacks

    Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

    153 Million Driver License Images Offered on Dark Web

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Russian drone hits Ukranian security headquarters, Zelensky says

    September 4, 2026

    US court ruling aggravates Brussels’ Google problem – POLITICO

    September 4, 2026

    Investigations launched into polling firm at centre of Reform UK allegations | Reform UK

    September 4, 2026

    Nigel Farage says his aides’ donor comments were ‘loose pub talk’

    September 4, 2026
    Latest Posts

    Interpol Leverages Global System to Curtail Fraud Payments

    July 31, 2026

    Repeat founder Ryan Williams raises $10M seed for an AI startup for private credit managers

    July 31, 2026

    Concerns raised over Northumberland council’s £900m debt

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Russian drone hits Ukranian security headquarters, Zelensky says

    September 4, 2026

    US court ruling aggravates Brussels’ Google problem – POLITICO

    September 4, 2026

    Investigations launched into polling firm at centre of Reform UK allegations | Reform UK

    September 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.