What happened
A critical vulnerability has been identified in Citrix NetScaler, tracked as CVE-2026-19490. This flaw allows for an authentication bypass, leading to potential remote code execution. The vulnerability has been actively exploited in the wild since at least September 3. Due to the nature of the flaw, affected systems are at significant risk of unauthorized access and control. No vendor patch was available at the time of disclosure, indicating the vulnerability is currently unmitigated by official security updates.
Who is affected
Organizations running Citrix NetScaler are affected by this security issue. Those with impacted deployments should consider the risk of unauthorised access to systems due to the authentication bypass. Since exploitation has been confirmed in active campaigns, all affected NetScaler instances are potentially vulnerable to remote code execution attempts carried out by malicious actors.
Recommended actions
- Identify all Citrix NetScaler deployments within the network infrastructure.
- Implement network controls to restrict access to NetScaler management interfaces from untrusted networks or IP addresses.
- Monitor for suspicious activity indicative of exploitation attempts targeting the vulnerable systems.
Indicators of compromise
Specific indicators of compromise have not been provided at this time.

