Find notable cyber news and cases, enriched with sources, timelines, and signals.

Citrix NetScaler authentication bypass (CVE-2026-19490)

Vulnerability
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-19490 is now being actively probed in the wild, putting exposed Citrix NetScaler appliances at risk of remote authentication bypass. Previdian observed matching PoC requests on 3 September from Australia, the United States and Germany. Citrix had already told admins to upgrade impacted builds as soon as possible, and NCC-BE later urged patching vulnerable appliances. No successful compromise has been confirmed, but the flaw has moved from disclosure into live targeting.

Related Happenings

Citrix NetScaler urgent patch guidance for CVE-2026-19490

Advisory/Mitigation
H score33 First: 04.09.2026 18:25 Last: 04.09.2026 18:25 Sources 1

How related: "We strongly recommend that customers review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible," Citrix warned in mid-August when it addressed the flaw and urged admins to patch it as soon as possible.

About this happening: Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, with NCC-BE later urging organization...

Citrix NetScaler ADC/Gateway memory overflow flaw (CVE-2026-8452)

Vulnerability
H score34 First: 27.08.2026 12:16 Last: 27.08.2026 12:16 Sources 1

About this happening: CVE-2026-8452 is an actively exploited memory overflow flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, including systems configured with Gateway V...

NetScaler ADC/Gateway arbitrary file read security flaw (CVE-2026-10816)

Vulnerability
H score30 First: 01.07.2026 06:54 Last: 01.07.2026 06:54 Sources 1

About this happening: Citrix's NetScaler ADC and NetScaler Gateway now have CVE-2026-10816, a 7.7 flaw that can expose files through unauthenticated arbitrary file read when managem...

CCB urgent patch warning for CVE-2026-41089 on Windows servers

Public Sector Action
H score48 First: 01.06.2026 15:30 Last: 01.06.2026 15:30 Sources 1

About this happening: Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...

CISA KEV order for CVE-2026-3055 on Citrix appliances

Public Sector Action
H score34 First: 31.03.2026 10:05 Last: 31.03.2026 10:05 Sources 1

About this happening: CISA added CVE-2026-3055 to the KEV Catalog and ordered FCEB agencies to secure Citrix NetScaler appliances by Thursday, April 2, turning an actively exploit...

Timeline

  1. 04.09.2026 03:00 2 articles · 1d ago

    NetScaler sensors detect PoC-matching requests for CVE-2026-19490

    Exploitation Observed

    Previdian said one of its NetScaler sensors received requests matching a credible proof-of-concept exploit for CVE-2026-19490 on 3 September from three distinct source IPs geolocated to Australia, the United States, and Germany, which the company assessed as exploitation attempts against vulnerable Citrix NetScaler appliances without confirming successful compromise.

    Show sources
  2. 19.08.2026 03:00 1 articles · 17d ago

    Citrix urges admins to patch CVE-2026-19490 on NetScaler appliances

    Initial Disclosure

    Citrix warned customers to review the NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments were affected, and upgrade impacted appliances to the recommended builds as soon as possible after addressing CVE-2026-19490 in its August 19 security advisory.

    Show sources