LIVE · cybersecurity feed
Live wire
CVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on HostCISA orders feds to patch actively exploited TrueConf Server flawsCVE-2026-69836 · Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
CVE-2026-19490critical

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

Citrix has released patches for two critical vulnerabilities affecting its NetScaler ADC and NetScaler Gateway products. The most severe, CVE-2026-19490, is an authentication bypass flaw with a CVSS score of 9.3 that could allow attackers to bypass login checks under specific configuration conditions. A second vulnerability, CVE-2026-19489, is a memory overflow issue with a CVSS score of 8.8 that can lead to denial of service.

zeroday.news ·

Citrix has issued an urgent advisory for customers to patch two critical vulnerabilities in its NetScaler ADC and NetScaler Gateway products, including a severe authentication bypass flaw identified as CVE-2026-19490. The company, through its parent Cloud Software Group, strongly recommends that users review the official security bulletin and upgrade affected appliances immediately.

The more critical of the two vulnerabilities, CVE-2026-19490, carries a CVSS v4.0 score of 9.3. This flaw allows an attacker to bypass login authentication checks through an alternate path, but only under specific configuration conditions. Affected appliances must be configured as a Gateway, supporting functions such as SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server. The vulnerability's exposure also depends on the firmware version and whether a SAML action is configured. For older firmware versions, the Gateway or AAA configuration alone is sufficient to meet the precondition, even without SAML being configured. The precise version thresholds vary between standard and FIPS builds.

Security teams can determine if their systems are exposed to CVE-2026-19490 by searching their NetScaler configuration for "add authentication samlAction" to identify SAML action setups, or for "add authentication vserver" and "add vpn vserver" to detect Auth or VPN virtual server configurations. As an alternative mitigation, if NetScaler Console (Service or on-prem) is in use and the NetScaler firmware version is 14.1-60.52 or 13.1-63.16 or higher, signatures can be applied. These versions include a "Global Deny Lists" feature that consumes and automatically applies signatures to NetScaler appliances managed via NetScaler Console.

The second vulnerability, CVE-2026-19489, is a memory overflow issue with a CVSS v4.0 score of 8.8. This flaw can lead to unpredictable behavior or a denial-of-service condition. Its applicability is also conditional, specifically when SIP ALG is enabled within a Large Scale NAT (LSN) group setup. To check for exposure to this second flaw, security teams should search their configuration for "add lsn group" combined with "sipalg."

The vulnerabilities affect several versions of NetScaler ADC and NetScaler Gateway: NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-73.32 NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.21 NetScaler ADC FIPS BEFORE 14.1-73.32 FIPS NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.277

Cloud Software Group's Senior VP of Engineering, Anil Shetty, confirmed that the bulletin applies to supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds. SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that utilize customer-managed NetScaler instances are also affected and require upgrades to the recommended builds.

Citrix has noted a specific behavior change after upgrading an ICA proxy setup to version 14.1-72.16 (or 13.1-63.18) or later. Any ICA session attempting to reconnect using a session ticket issued by the older, pre-upgrade version will be dropped. Users will need to relaunch their sessions, which Citrix states is a security measure rather than an unintended side effect of the upgrade.

As of August 19, 2026, there have been no observed instances of exploitation for CVE-2026-19490. However, cybersecurity researchers are urging organizations to prioritize patching immediately, citing a historical trend of rapid exploitation of Citrix product vulnerabilities once they become public. At the time of Citrix’s advisory, the NetScaler images available on AWS, Azure, and GCP marketplaces had not yet been updated with the patched builds.

netscalercitrixvulnerabilityauthentication bypassdenial of service
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

AWS Security makes an inscrutable choice

Quarantining leaked credentials is not good enough

cloud security

Cloudflare Launches Bot Preference Sync for AI Traffic Management

Cloudflare has introduced Bot Preference Sync, a new feature designed to simplify the management of AI bot traffic. This tool automatically updates a website's robots.txt file to align with the user's AI bot configuration settings. The goal is to prevent discrepancies between stated preferences and enforced rules, ensuring better control over how AI crawlers access and use website content.

ai

Say it once: introducing Bot Preference Sync

Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.

CVE-2024-3094high

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Attackers are increasingly targeting the software development lifecycle (SDLC) supply chain by compromising developer tools, CI/CD pipelines, and open-source packages. Recent attacks like the ChainDrop npm worm demonstrate sophisticated methods to steal credentials, backdoor developer environments, and propagate malware. Securing the SDLC requires a shift from reactive code scanning to strict execution control and continuous visibility across developer endpoints, build pipelines, and cloud runtimes.

patch

Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii),

security

Lawmakers call for investigation into impact of CISA staffing cuts

Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.