The Dutch National Cyber Security Centre (NCSC) warned that attackers were actively scanning for Citrix ADC and Citrix Gateway—formerly NetScaler—systems vulnerable to CVE-2019-19781. The flaw could allow an unauthenticated remote attacker to execute code and gain direct access to internal networks and systems; no vendor patch was available when the warning was issued, making Citrix-provided mitigations the immediate defensive measure.
Organizations were urged to identify internet-exposed Citrix appliances, deploy and validate the mitigations, assess their status with Citrix’s available checking tool, and install the vendor update as soon as released. The NCSC cautioned that compromise could have occurred before mitigations were applied or where they failed, recommending specialist incident-response review for affected systems; XML files created and invoked under vpns/portal/ could indicate attempted code execution, although their absence did not exclude intrusion.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
The NCSC urged organizations to apply Citrix mitigations and assess exposed systems, warning that servers could already have been compromised before mitigations were deployed or where mitigations failed. It recommended specialist investigation of potentially affected systems and noted XML files in vpns/portal/ directories as possible indicators of attempted code execution.
The NCSC warned that attackers were actively searching for vulnerable Citrix ADC and Citrix Gateway servers. No active exploitation had been observed at that time, but successful unauthenticated exploitation could provide direct access to local networks and systems.
The Dutch National Cyber Security Centre had previously issued a High/High security advisory concerning the Citrix ADC and Citrix Gateway vulnerability.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
ncsc.nl
Open sourcencsc.nl
Open sourcesupport.citrix.com
Open sourcesupport.citrix.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.