LIVE · cybersecurity feed
Live wire
CVE-2026-69836 · Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code ExecutionManic: The Android Malware That Exfiltrates Data Even When the Phone Is OfflineHackers poison arrayref Rust crate to push infostealer malwareNSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCsSenators press TikTok over withholding of safety features for some usersAI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical InfrastructureChatGPT for Teens tackles risky chats and homework shortcutsCritical Elementor Pro bug exposes WordPress sites to RCE attacksNew Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat DataFrequently asked questions about the active threat to Siemens S7 Series PLCs
CVE-2026-19489critical

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Citrix has released critical security updates for NetScaler ADC and NetScaler Gateway to address two vulnerabilities. The most severe, CVE-2026-19490 (CVSS 9.3), allows for authentication bypass on specific configurations, including those acting as Gateways or AAA servers with SAML actions. A second flaw, CVE-2026-19489 (CVSS 8.8), is a memory overflow leading to potential denial-of-service when the SIP ALG is enabled.

zeroday.news ·

Citrix has issued urgent security updates for its NetScaler ADC and NetScaler Gateway products to remediate two significant vulnerabilities. The more critical of these, tracked as CVE-2026-19490, carries a CVSS score of 9.3 and enables an authentication bypass. This flaw specifically impacts certain configurations, particularly those where the NetScaler appliance functions as a Gateway or an AAA server utilizing SAML actions.

The authentication bypass vulnerability, CVE-2026-19490, allows an unauthenticated attacker to circumvent the login process. This is particularly concerning for appliances configured as NetScaler Gateways, which are commonly used to provide secure remote access to internal networks and applications. When acting as an AAA (Authentication, Authorization, and Accounting) server with SAML (Security Assertion Markup Language) actions enabled, the flaw could permit unauthorized access by bypassing the intended identity verification steps. Such a bypass could grant an attacker access to protected resources without valid credentials.

The second vulnerability, CVE-2026-19489, is rated with a CVSS score of 8.8. This flaw is described as a memory overflow issue. It specifically affects NetScaler instances where the Session Initiation Protocol Application Layer Gateway (SIP ALG) is enabled. A successful exploit of this vulnerability could lead to a denial-of-service condition, disrupting the availability of the affected NetScaler services.

For CVE-2026-19490, the primary mitigation involves applying the security updates provided by Citrix. Given the nature of an authentication bypass, organizations are strongly advised to prioritize these patches, especially for internet-facing NetScaler Gateway instances or those serving as critical AAA infrastructure. For CVE-2026-19489, patching is also the recommended course of action. Additionally, organizations that do not utilize the SIP ALG functionality may consider disabling it as a temporary measure until patches can be applied, though patching remains the definitive solution.

Authentication bypass vulnerabilities are a severe class of security flaw because they undermine the fundamental security control of verifying user identity. Products like NetScaler ADC and Gateway are often deployed at the network edge, making them high-value targets for attackers. The ability to bypass authentication on such devices can lead to unauthorized network access, data breaches, or further internal network compromise.

Memory overflow vulnerabilities, while potentially leading to denial-of-service, can sometimes be exploited for arbitrary code execution in more complex scenarios, though the reported information specifies denial-of-service for this particular flaw. Products that handle network traffic, especially those with specialized application layer gateways like SIP ALG, are often susceptible to such issues due to the complexities of parsing and processing diverse network protocols.

Organizations utilizing Citrix NetScaler ADC and NetScaler Gateway products should immediately review their configurations to determine if they are affected by these vulnerabilities and apply the provided security updates without delay. Proactive patching and adherence to vendor security advisories are critical practices for maintaining the integrity and availability of network infrastructure components that often serve as the first line of defense.

netscalercitrixauthentication bypassvulnerabilitydenial of service
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

vulnerability

Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.

Secure Workload Software has five nasty flaws and even SaaS users have updates to install

finance

A $25 template helped scammers build hundreds of phantom bank domains

A phrase on a suspicious website turned into an investigation of phantom banks built to support scams, according to new research from Allure Security. Molly DeQuattro, the company’s VP of Operations, was reviewing a domain that resembled the brand of one of its financial services clients. The page carried none of that client’s branding. It presented an unrelated bank instead. One phrase caught her

patch

Nearly half of enterprises have no one leading PQC migration

Enterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate their transition to post-quantum cryptography (PQC), according to new research from Axiad. Who owns PQC migration? (Source: Axiad) Organizations need to know where certificates, cryptographic keys and algorithms are used before they can plan a

security

Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)

In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#;x26;#;39;s left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ... This is that method. Also, remember when we discussed yesterday about the beta graph commands in the Microsoft.Graph.Beta library? We&#;x26;#;39;ll u

security

Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)

One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise. One log that really bears looking at is the log of successful and failed logins. the call for that is: