bleeping-computer · Crawled Sep 4, 2026

Critical Citrix NetScaler auth bypass now leveraged in attacks

3 IoCs
Read original article ↗

AI Summary

Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler appliances, tracked as CVE-2026-19490, which allows unprivileged remote actors to bypass authentication when the appliance is configured as an AAA virtual server or Gateway. Exploitation attempts have been observed from multiple IP addresses geolocated to Australia, the United States, and Germany, following the release of a public proof-of-concept. The Centre for Cybersecurity Belgium and vulnerability intelligence firm Previdian have issued warnings urging administrators to patch affected systems immediately.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
IP 93[.]184[.]216[.]34 Details →
IP 203[.]0[.]113[.]22 Details →
IP 198[.]51[.]100[.]17 Details →