news.mlab.sh
Back to the feed
vulnerability

Critical NetScaler Vulnerability Exploited in Attacks

CriticalCVSS 9.3
Summary

A critical NetScaler vulnerability (CVE-2026-19490) is being actively exploited in the wild, prompting a CISA warning and urging immediate patching. Threat actors have been targeting NetScaler appliances globally, highlighting the high value of these systems as targets.

The US Cybersecurity and Infrastructure Security Agency (CISA) issued a warning on Wednesday regarding a critical NetScaler vulnerability (CVE-2026-19490) that is currently being exploited by threat actors. This vulnerability affects all NetScaler ADC and NetScaler Gateway appliances when configured as a gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server. Citrix released a patch on August 19th, following a warning from cybersecurity firm Rapid7, who anticipated that exploitation would begin shortly due to the prevalence of NetScaler deployments within enterprise environments. Rapid7’s analysis indicated that threat actors were sending matching requests to sensors across three countries as of September 3rd, a day after an exploit targeting the vulnerability was published on GitHub. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, requesting federal agencies to patch it within three days, adhering to BOD 26-04’s requirements. This incident underscores the importance of timely patching and proactive security measures for organizations utilizing NetScaler appliances.

Read the full article at SecurityWeek