By Heath Callahan
Publication Date: 2026-09-10 00:31:00
Analysis
Previdian recorded 10 exploitation attempts from six attacker IPs within 24 hours of a public PoC release. The 15-day patch-to-exploitation window shows threat actors weaponizing Citrix disclosures faster than enterprises can deploy fixes.
A 15-day window separated the disclosure of CVE-2026-19490, a critical authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway, and the first observed exploitation attempts. Disclosed on August 19, 2026, the vulnerability carries a CVSS v4.0 score of 9.3 and affects versions 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, including FIPS and NDcPP builds. By September 3, 2026, following the release of a proof-of-concept (PoC), threat intelligence firm Previdian recorded active exploitation attempts against its sensor network.
This incident expands the authentication gap pattern into VPN gateway infrastructure. The pattern has previously appeared in PaperCut, N-able, Microsoft, SAP, Ivanti, and Check Point. By…


