Attackers are now probing a critical Citrix NetScaler authentication-bypass vulnerability, according to BleepingComputer, which cites vulnerability intelligence company Previdian and a warning from Belgium’s cybersecurity authority. The flaw is tracked as CVE-2026-19490. BleepingComputer reports that it can let unprivileged attackers remotely bypass authentication when a NetScaler appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy deployments. Whether a deployment is exposed depends on the NetScaler firmware version and whether SAML Action is configured. Citrix addressed the issue in mid-August and urged administrators to review its NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to recommended builds. BleepingComputer notes that Citrix’s August 19 advisory had not yet marked CVE-2026-19490 as actively exploited at the time of the report. The exploitation signal comes from Previdian. Founder and security researcher Ryan Dewhurst told BleepingComputer that attackers began targeting the flaw after a “credible” proof-of-concept exploit was published online. Dewhurst said one of Previdian’s NetScaler sensors saw requests matching the proof of concept on September 3 from three distinct source IPs geolocated to Australia, the United States, and Germany. The important caveat: Previdian characterized the activity as evidence of exploitation attempts, not proof that real-world systems have been compromised. That distinction matters for response triage. The report supports urgent patching and hunting for probes, but it does not establish a known intrusion campaign with confirmed successful access. Belgium’s Centre for Cybersecurity Belgium, the country’s National Cybersecurity Coordination Centre, also warned Friday of exploitation attempts targeting CVE-2026-19490, according to BleepingComputer. The Belgian authority urged administrators to prioritize patching vulnerable Citrix NetScaler appliances on their networks. The exposed surface is not small. BleepingComputer says Internet threat watchdog Shadowserver tracks more than 22,000 NetScaler ADC appliances and nearly 1,700 Gateway instances exposed online. The report adds that those figures do not show how many are honeypots, how many have vulnerable configurations, or how many have already been patched. The NetScaler line has recent precedent for fast-moving exploitation. BleepingComputer notes that Citrix urged administrators to patch two other NetScaler flaws, CVE-2026-3055 and CVE-2026-4368, in March, shortly before threat actors began exploiting them. The Cybersecurity and Infrastructure Security Agency later added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch vulnerable Citrix appliances within three days. Who benefits: Defenders benefit from early warning before confirmed compromise is reported. Organizations that already applied Citrix’s recommended builds are in a stronger position, assuming their affected deployments were fully covered. Who's exposed: Organizations running NetScaler ADC or NetScaler Gateway in the affected configurations are the exposed population. The public exposure counts are broad and do not indicate which systems are actually vulnerable or unpatched.