Critical NetScaler authentication bypass exploited in wild

Citrix released patches for CVE-2026-19490, a critical authentication bypass flaw (CVSS 9.3) in NetScaler ADC and NetScaler Gateway, by August 20, 2026, after the vulnerability was actively exploited by unauthenticated attackers. The flaw allows remote attackers to bypass authentication controls via an alternate path.

7 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-19490 (CVSS 9.3) is a critical NetScaler authentication bypass in NetScaler Gateway and ADC. Patch now to block unauthenticated access. # NetScaler # Citrix # CVE202619490 # AuthBypass # Info

mastodon:infosec-exchangeother41d ago kagi ↗

CVE-2026-19490 (CVSS 9.3) is a critical NetScaler authentication bypass in NetScaler Gateway and ADC. Patch now to block unauthenticated access. # NetScaler # Citrix # CVE202619490 # AuthBypass # InfoSec https:// securityonline.info/netscaler- authentication-bypass-cve-2026-19490/?utm_source=mastodon&utm_medium=jetpack_social

Citrix urges customers to patch critical NetScaler bypass flaw

kite:cybersecurityother40d ago kagi ↗

Citrix released fixes for two vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway deployments, including CVE-2026-19490, a critical authentication-bypass flaw rated CVSS 9.3. The flaw can affect appliances configured as a Gateway or AAA virtual server, depending on version and configuration [bleepingcomputer.com#1][thehackernews.com#1][securityweek.com#1][nsm.no#1]. The second

Citrix has released patches for CVE-2026-19490, a CVSS 9.3 authentication bypass in NetScaler ADC and Gateway. An unauthenticated remote attacker can exploit the flaw via an alternative path to bypass

mastodon:infosec-exchangeother40d ago kagi ↗

Citrix has released patches for CVE-2026-19490, a CVSS 9.3 authentication bypass in NetScaler ADC and Gateway. An unauthenticated remote attacker can exploit the flaw via an alternative path to bypass authentication on appliances configured as SSL VPN, ICA Proxy, CVPN, RDP Proxy, or AAA servers. # CitrixBleb # NetScalerVuln # CVSS9 # RemoteAccessSecurity https:// cyberworldops.eu/en/netscaler- cri

Citrix Patches Critical Authentication Bypass in NetScaler ADC and Gateway Citrix patched two vulnerabilities in NetScaler ADC and Gateway, including an authentication bypass and a memory overflow. Th

mastodon:infosec-exchangeother40d ago kagi ↗

Citrix Patches Critical Authentication Bypass in NetScaler ADC and Gateway Citrix patched two vulnerabilities in NetScaler ADC and Gateway, including an authentication bypass and a memory overflow. These flaws allow unauthenticated attackers to gain unauthorized access or cause a denial of service on perimeter networking equipment. **If you run NetScaler ADC or Gateway, update ASAP to 14.1-73.32,

CVE-2026-19490 | 9.3 Critical | Authentication Bypass Using an Alternate Path → An unauthenticated remote attacker can bypass authentication controls on NetScaler appliances configured as a Gateway (S

mastodon:infosec-exchangeother40d ago kagi ↗

CVE-2026-19490 | 9.3 Critical | Authentication Bypass Using an Alternate Path → An unauthenticated remote attacker can bypass authentication controls on NetScaler appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server, gaining access to protected resources without valid credentials. → Exploitability depends on the NetScaler firmware version and whether

Citrix NetScaler Flaws Under Active Attack Following Exploit Release Citrix NetScaler ADC and Gateway appliances are being exploited via a critical SAML memory overflow vulnerability (CVE-2026-8452) t

mastodon:infosec-exchangeother39d ago kagi ↗

Citrix NetScaler Flaws Under Active Attack Following Exploit Release Citrix NetScaler ADC and Gateway appliances are being exploited via a critical SAML memory overflow vulnerability (CVE-2026-8452) that allows pre-authentication remote code execution. Attackers are targeting perimeter devices to gain unauthorized access to internal corporate networks following the release of public proof-of-conce