logo

A Second Look at CVE-2019-19781 (Citrix NetScaler / ADC)

ID: 9fc21d82-0f70-5373-8f44-fb293b71ed66

STIX ID: report--9fc21d82-0f70-5373-8f44-fb293b71ed66

Feed Name: Fox-IT blog

Threat Score
85/100

Date Published: 2020-07-01

Date Updated: 2026-04-27

Author: Fox It

...
...

**Executive summary:** This report revisits CVE-2019-19781 (Citrix NetScaler/ADC), documents widespread active exploitation and deployment of webshells/backdoors (including NOTROBIN 'palware' that removes competing backdoors), provides IOCs and statistics showing thousands of vulnerable and compromised devices, and describes a newly demonstrated single-request exploit that bypasses adversary patching and common detection assumptions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.