LIVE · cybersecurity feed
Live wire
vendor2 exploited in the wild

Citrix

7 CVEs published in the last four months and 10 stories. Exploited flaws first.

Critical3
High4
Medium0
Exploited (KEV)2

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-3055exploited9.8criticalnetscaler application delivery controllerInsufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memor166d ago
CVE-2026-8452exploited9.8criticalnetscaler application delivery controllerMemory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior an67d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-3055exploited9.8criticalnetscaler application delivery controllerInsufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memor166d ago
CVE-2026-8452exploited9.8criticalnetscaler application delivery controllerMemory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior an67d ago
CVE-2026-86559.8criticalnetscaler application delivery controllerMultiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneo67d ago
CVE-2026-84517.5highnetscaler application delivery controllerInsufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or67d ago
CVE-2026-134747.5highnetscaler application delivery controllerDenial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTT67d ago
CVE-2026-108167.5highnetscaler application delivery controllerArbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Manage67d ago
CVE-2026-108177.5highnetscaler application delivery controllerInsufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeSta67d ago

Filter the full tracker by Citrix

Our coverage of Citrix

CVE-2026-73570

Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Unpatched Zimbra servers are falling to CVE-2026-73570 attacks At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. AI supply chain risk is showing up in developer workflows first In this Help Net Sec

vulnerabilityhigh

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

CISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. [...]

security

Citrix UniconOS dual boot turns Windows endpoints into their own recovery device

Citrix announced Citrix UniconOS dual boot, a new endpoint resiliency capability designed to help organizations recover access to work in minutes — without spare hardware, central reimaging or prolonged business downtime. Available now as part of Citrix UniconOS Release 7 2607, dual boot turns every compatible Windows endpoint into its own recovery device: an isolated, hardened Citrix UniconOS env

CVE-2026-19490critical

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

Citrix has released patches for two critical vulnerabilities affecting its NetScaler ADC and NetScaler Gateway products. The most severe, CVE-2026-19490, is an authentication bypass flaw with a CVSS score of 9.3 that could allow attackers to bypass login checks under specific configuration conditions. A second vulnerability, CVE-2026-19489, is a memory overflow issue with a CVSS score of 8.8 that can lead to denial of service.

CVE-2026-19489critical

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Citrix has released critical security updates for NetScaler ADC and NetScaler Gateway to address two vulnerabilities. The most severe, CVE-2026-19490 (CVSS 9.3), allows for authentication bypass on specific configurations, including those acting as Gateways or AAA servers with SAML actions. A second flaw, CVE-2026-19489 (CVSS 8.8), is a memory overflow leading to potential denial-of-service when the SIP ALG is enabled.

vulnerability

Citrix urges admins to patch new NetScaler flaws as soon as possible

Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. [...]

vulnerabilitycritical

Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler

Remote, unauthenticated attackers could exploit the critical-severity flaw without user interaction. The post Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler appeared first on SecurityWeek.

CVE-2026-19490critical

CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway

Overview On August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges. NetScaler ADC and NetScaler Gatew

vulnerability

CitrixBleed-ing Again? NetScaler Vulnerability Under Attack

Attackers wasted little time targeting the latest memory disclosure flaw in Citrix's NetScaler products, after researchers published a proof-of-concept exploit (PoC).

CVE-2025-5777

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. "Although tactics differ between affiliates, common patterns emerged in t