Source: BleepingComputer
Author: Sergiu Gatlan
URL: https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/
ONE SENTENCE SUMMARY:
Attackers are probing Citrix NetScaler CVE-2026-19490 auth-bypass flaw; agencies urge urgent patching amid PoC-driven exploitation attempts worldwide.
MAIN POINTS:
- Previdian reports in-the-wild targeting of critical Citrix NetScaler vulnerability CVE-2026-19490.
- Flaw enables remote authentication bypass by unprivileged attackers under specific NetScaler configurations.
- Affected setups include AAA virtual server and Gateway modes like SSL VPN and ICA Proxy.
- Exploitability depends on firmware version and whether SAML Action is configured.
- Citrix patched the issue mid-August and urged immediate upgrades to recommended builds.
- Citrix advisory (Aug 19) did not yet confirm active exploitation.
- Credible PoC publication preceded observed exploitation-like requests, per researcher Ryan Dewhurst.
- NetScaler sensor saw matching PoC attempts from IPs in Australia, US, and Germany.
- Belgium’s NCC-BE also warned of exploitation attempts and prioritized patching guidance.
- Shadowserver observes 22,000+ ADC and 1,700+ Gateway instances exposed, patch status unknown.
TAKEAWAYS:
- Patch NetScaler appliances promptly, prioritizing AAA and Gateway deployments.
- Validate firmware and SAML-related configuration to determine actual exposure.
- Treat publicly released PoCs as immediate risk accelerants for mass scanning.
- Monitor for exploit-pattern requests, but distinguish attempts from confirmed compromises.
- Citrix NetScaler remains a recurring target, with multiple prior flaws quickly exploited.