netscaler news
5 stories
Hackers exploit Citrix NetScaler zero-day to deploy web shells
Attackers have been exploiting two zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to gain root access, deploy web shells, and infiltrate internal networks. Citrix confirmed the active exploitation of both flaws and released security updates to address them.

Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services
Attackers have exploited two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to compromise government agencies, financial services firms, educational institutions, and legal and professional services organizations across North America and Europe. The exploitation campaign began in early September, weeks…

Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun exploiting a critical authentication bypass vulnerability in Citrix NetScaler appliances, identified as CVE-2026-19490. The flaw allows unprivileged remote attackers to bypass authentication when the NetScaler appliance is configured as a AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy). The specific impact depends on the NetScaler firmware version…

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)
Citrix has issued an urgent advisory for customers to patch two critical vulnerabilities in its NetScaler ADC and NetScaler Gateway products, including a severe authentication bypass flaw identified as CVE-2026-19490. The company, through its parent Cloud Software Group, strongly recommends that users review the official security bulletin and upgrade affected appliances immediately.

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Citrix has issued urgent security updates for its NetScaler ADC and NetScaler Gateway products to remediate two significant vulnerabilities. The more critical of these, tracked as CVE-2026-19490, carries a CVSS score of 9.3 and enables an authentication bypass. This flaw specifically impacts certain configurations, particularly those where the NetScaler appliance functions as a Gateway or an…