Citrix disclosed CVE-2026-19490, a critical NetScaler ADC and NetScaler Gateway flaw with a CVSS v4 score of 9.3. In affected Gateway and AAA virtual-server configurations—including SSL VPN, ICA Proxy, CVPN, and RDP Proxy—an unauthenticated remote attacker can bypass authentication and may execute arbitrary code. A public proof of concept emerged, exploitation attempts were observed by sensors, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.
Citrix also patched CVE-2026-19489, a high-severity memory-overflow denial-of-service vulnerability affecting appliances that have SIP ALG enabled on an LSN group. No workarounds are available for either issue; organizations running customer-managed NetScaler appliances should urgently apply Citrix updates and investigate internet-exposed or potentially affected systems for evidence of compromise.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
CISA warned that threat actors were exploiting CVE-2026-19490 in attacks and directed U.S. federal agencies to remediate the vulnerability within three days under Binding Operational Directive 26-04. CISA did not disclose technical details of the observed exploitation.
Security researchers recorded 56 attempted exploits targeting honeypot systems for CVE-2026-19490 from September 3 through September 8. The reporting confirmed attempted exploitation but did not independently verify successful compromises of production systems.
Previdian observed exploitation attempts against CVE-2026-19490 within 24 hours of public proof-of-concept availability and through at least 6 September. It recorded 10 attempts from six unique IP addresses, but the telemetry did not confirm successful compromises.
The Australian Cyber Security Centre issued an alert urging Australian organizations to prioritize patching affected NetScaler appliances, noting that internet-facing appliances are frequent initial-access targets.
A public proof of concept for the critical NetScaler Gateway and AAA authentication-bypass vulnerability CVE-2026-19490 reportedly became available around 3 September 2026.
Citrix disclosed CVE-2026-19489, a high-severity memory-overflow denial-of-service flaw, and CVE-2026-19490, a critical unauthenticated authentication-bypass flaw, affecting NetScaler ADC and NetScaler Gateway. The company addressed both issues in bulletin CTX696939 and provided patched releases, stating that no workarounds were available.
Bishop Fox documented how attacker-controlled decoded RelayState lengths can trigger packet-engine crashes or create anonymous sessions on vulnerable NetScaler Gateway and AAA virtual servers. The report described configuration-dependent HTTP(S) proxying from anonymous Gateway sessions, a demonstrated credential-dependent route to root command execution via NITRO, and a safe single-request detection method.
Brazil's CTIR Gov issued a TLP:CLEAR alert on CVE-2026-19490, identifying affected NetScaler ADC and Gateway 13.1 and 14.1 release lines and urging immediate application of Citrix's fixes. The notice also stated that ReGIC member agencies must urgently remediate vulnerabilities identified in alerts and recommendations.
CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog, indicating that exploitation had been observed. CERT-SE urged organizations to apply Citrix's updates and investigate potentially affected systems for evidence of intrusion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
10 references tracked. Mallory keeps watching after this page renders.
gov.br
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcebishopfox.com
Open sourcecert.se
Open sourcetriskelelabs.com
Open sourcecirt.gy
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.