High-Severity NetScaler Vulnerability Exploited in Cyber Attacks

www.news4hackers.com-high-severity-netscaler-vulnerability-exploited-in-cyber-attacks-high-severity-netscaler-vulnerability-exploited-in-cyber-attacks

Critical NetScaler Vulnerability Under Active Exploitation, CISA Issues Urgent Alert

CISA’s Urgent Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding the active exploitation of a critical vulnerability in Citrix NetScaler products. The flaw, designated CVE-2026-19490 with a CVSS score of 9.3, affects all NetScaler ADC and Gateway appliances configured as a gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server.

Vulnerability Details

Citrix addressed the issue on August 19, but cybersecurity firm Rapid7 had previously warned that the vulnerability could be exploited remotely without authentication, noting that threat actors were likely to begin leveraging it soon due to the widespread deployment of NetScaler in enterprise environments.

CISA’s KEV Catalog Inclusion

CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday, mandating federal agencies to resolve the issue within three days in accordance with BOD 26-04 guidelines.

Exploitation Reports

While the agency has not disclosed specifics about observed attacks, the alert follows reports from Previdian founder Ryan Dewhurst, who indicated that hackers began exploiting the flaw shortly after a proof-of-concept (PoC) emerged. Dewhurst stated that three IP addresses across three countries sent matching requests to his organization’s sensors on the same day as the PoC’s release.

Previdian’s Findings

Data from Previdian reveals that exploitation of the vulnerability has been ongoing since at least September 3, one day after an exploit targeting CVE-2026-19490 was published on GitHub.

Rapid7’s Warning

Rapid7 emphasized that the flaw’s characteristics make it a high-priority risk, urging organizations to apply patches immediately. The firm highlighted that NetScaler appliances are frequently targeted due to their role in critical infrastructure and remote access functions.

Exploit Impact

The vulnerability allows attackers to execute arbitrary code on affected systems without requiring authentication, making it a significant threat to environments reliant on NetScaler for secure network access.

Citrix’s Patch and Industry Response

Citrix’s patch, released in August, addresses the flaw, but the rapid transition from public exploit disclosure to active attacks underscores the urgency for enterprises to implement mitigations. Security experts have warned that delayed remediation could lead to widespread compromise, particularly in sectors handling sensitive data.

Recommendations

Organizations are advised to review their NetScaler configurations, apply the latest patches, and monitor for signs of unauthorized access. The incident highlights the risks associated with zero-day vulnerabilities in widely used infrastructure software and the importance of proactive vulnerability management.

“Three IP addresses across three countries sent matching requests to my organization’s sensors on the same day as the PoC’s release,” said Ryan Dewhurst, founder of Previdian.



About Author

en_USEnglish