Attackers have begun attempting to exploit CVE-2026-19490, a critical authentication-bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway. Remote, unauthenticated actors can bypass authentication on susceptible appliances configured as AAA virtual servers or Gateway services when affected firmware versions and SAML Action settings are present; sensor data from Previdian confirms exploitation attempts, though not confirmed successful compromises.
Citrix issued fixes on August 19 and urged customers to upgrade affected appliances. Australia’s ACSC and Belgium’s national cybersecurity coordination center have also called for urgent patching, warning that internet-facing edge devices are frequent initial-access targets. Organizations should identify exposed NetScaler instances and vulnerable SAML/VPN configurations, apply the relevant updates, and continue monitoring appliances after remediation. Citrix also disclosed CVE-2026-19489, a memory-overflow flaw affecting deployments using SIP ALG with Large Scale NAT groups.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued Alert AL26-019 covering CVE-2026-19490 and CVE-2026-19489 in Citrix NetScaler ADC and Gateway. It urged organizations to identify vulnerable SAML, Gateway, and AAA configurations, urgently upgrade to fixed releases, and monitor logs and network activity for unauthorized access.
A Previdian NetScaler sensor received requests matching the CVE-2026-19490 proof-of-concept from three source IP addresses geolocated to Australia, the United States, and Germany. Previdian characterized the activity as exploitation attempts, not evidence of successful intrusions.
Citrix issued an advisory and released fixes for CVE-2026-19489, a memory-overflow flaw, and CVE-2026-19490, an authentication-bypass flaw affecting certain NetScaler ADC and Gateway configurations.
Belgium's Centre for Cybersecurity and National Cybersecurity Coordination Centre warned organizations about exploitation attempts against CVE-2026-19490 and urged administrators to prioritize patching vulnerable NetScaler appliances.
Australia's ACSC urged organizations to identify affected NetScaler configurations, apply Citrix's updates, and monitor patched environments for suspicious activity. It said it had no information that a particular Australian sector was being targeted.
After a credible proof-of-concept for CVE-2026-19490 was published online, attackers began attempting to target the NetScaler authentication-bypass vulnerability. The source does not confirm any successful compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcebleepingcomputer.com
Open sourcethecyberexpress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.