What 239,000 Exposed NetScaler Instances Tell You About Remote Access Risk
The authentication bypass vulnerability CVE-2026-19490 in Citrix NetScaler allows attackers to target applications without credentials. ZoomEye found 239,174 NetScaler instances, of which 92,867 have a web interface; an exploit appeared 15 days after the patch.
- ZoomEye: 239,174 NetScaler instances, 92,867 with web interface
- Shadowserver: over 22,000 exposed ADC and about 1,700 Gateway
- Patch released August 19, 2026; exploit on September 2
- CISA added CVE to KEV on September 9 with September 12 deadline
Read next
Security