CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

CISA added a critical Citrix NetScaler authentication bypass flaw (CVE-2026-19490) to its Known Exploited Vulnerabilities catalog after observing in-the-wild attacks targeting the issue. Federal civilian agencies must apply vendor mitigations by September 12, 2026.

CVE-2026-19490 affects Citrix NetScaler ADC and NetScaler Gateway appliances configured as an Authentication, Authorization and Auditing virtual server or as a Gateway service. This includes deployments supporting SSL VPN, ICA Proxy, CVPN, and RDP Proxy functions.

The flaw is categorized as CWE-288, Authentication Bypass Using an Alternate Path or Channel. It could allow a remote, unauthenticated attacker to bypass login protections and access functionality that normally requires valid credentials.

Because NetScaler appliances are commonly deployed at the edge of corporate networks to provide remote access, successful exploitation could expose sensitive applications and internal services.

Citrix released security updates for the vulnerability on August 19, 2026. Exploitation activity was subsequently detected after a credible proof-of-concept exploit became publicly available.

Citrix NetScaler Authentication Bypass Vulnerability Exploited

Security researchers observed attack requests targeting honeypot systems beginning on September 3, with 56 attempts logged through September 8. Available reporting indicates attempted exploitation but does not independently confirm that attackers successfully compromised production environments using the flaw.

The issue affects NetScaler ADC and NetScaler Gateway version 14.1 releases before 14.1-73.32, as well as version 13.1 releases before 13.1-63.21.

Citrix NetScaler ADC FIPS builds before 14.1-73.32, and NetScaler ADC FIPS and NDcPP builds before 13.1-37.277 are also affected. Organizations should upgrade to the corresponding fixed builds or later releases.

Newer vulnerable installations require specific configuration conditions, including use as a SAML identity provider. Earlier builds can be affected when configured as a Gateway or AAA virtual server.

Administrators should therefore identify all internet-facing NetScaler instances, confirm their firmware version, and review AAA, Gateway, VPN, and SAML settings.

CISA’s inclusion of CVE-2026-19490 in the KEV catalog means agencies must prioritize remediation under Binding Operational Directive 26-04. The agency also requires forensic triage for affected assets, emphasizing that patching alone may not be sufficient when exposure or suspicious activity is identified.

Security teams should examine appliance logs for anomalous authentication events, unexpected requests, configuration modifications, new administrator sessions, and unusual outbound connections.

Organizations should isolate potentially compromised appliances, preserve evidence, rotate relevant credentials, and assess downstream systems accessible through the affected gateway.

No ransomware use has been confirmed for CVE-2026-19490 so far. However, the combination of public exploit code, internet-facing VPN infrastructure, and observed exploitation attempts makes patching an urgent priority for all organizations running affected Citrix NetScaler deployments.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks appeared first on Cyber Security News.