← nejvýznamnější zprávy

SPOJENO AI KEV ✓ EPSS 0.06

Critical Citrix NetScaler auth bypass now leveraged in attacks

Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]

11 zpráv z 9 zdrojů · první 19. 8. 18:46 · poslední 9. 9. 15:50 CZ · EN/orig

Citrix SE US CA IT NL FI FR

tg: zneužíváno tg: zranitelnost tp: identita

CVE v události 2

CVEhodnoceníKEVEPSS
CVE-2026-19489 8.8 4.0 · NetScaler 0.00
CVE-2026-19490 9.3 4.0 · NetScaler KEV ✓ 0.06

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.3.

Jak se o tom psalo 11

  1. · CERT-SE SE

    Kritisk sårbarhet i Citrix NetScaler ADC och NetScaler Gateway

    Citrix har publicerat information om en kritisk sårbarhet som påverkar Citrix NetScaler ADC och NetScaler Gateway. Sårbarheten, CVE-2026-19490, har fått CVSS v.4-klassning på 9.3. [1, 2]

  2. · CISA KEV US

    Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVE-2026-19490)

    CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog. Affected product: Citrix NetScaler. Remediation due date: 2026-09-12.

  3. · Cyber Centre Kanada CA

    AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489

    Number: AL26-019Date: September 4, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre…

  4. · BleepingComputer US nadpis události

    Critical Citrix NetScaler auth bypass now leveraged in attacks

    Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]

  5. · CERT-SE SE

    Kritisk sårbarhet i Citrix NetScaler ADC och NetScaler Gateway

    Citrix har publicerat information om en kritisk sårbarhet som påverkar Citrix NetScaler ADC och NetScaler Gateway. Sårbarheten, CVE-2026-19490, har fått CVSS v.4-klassning på 9.3. [1, 2]

  6. · CSIRT Itálie (ACN) IT

    Vulnerabilità in prodotti Citrix

    Aggiornamenti di sicurezza Citrix sanano due vulnerabilità con gravità "alta" nei prodotti NetScaler ADC (precedentemente noto come Citrix ADC) e NetScaler Gateway (precedentemente noto come Citrix Gateway).

  7. · NCSC-NL NL

    NCSC-2026-0318 [1.00] [M/M] Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gateway

    Citrix heeft kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De kwetsbaarheid met kenmerk CVE-2026-19489 betreft een memory overflow in NetScaler ADC en NetScaler Gateway, wanneer de producten zijn geconfigureerd als SIP ALG binnen een Large Scale NAT (LSN) groep. Deze fout in de geheugenallocatie kan leiden tot onvoorspelbaar gedrag of een denial of service, waardoor de normale werking van het systeem verstoord kan worden. De kwetsbaarheid met kenmerk CVE-2026-19490 maakt het…

  8. · NCSC-FI FI

    Citrix Netscaler ADC ja Gateway -tuotteissa kriittisiä haavoittuvuuksia

    Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 9.3, CVEs: CVE-2026-19489, CVE-2026-19490, Summary: Citrix on julkaissut Netscaler ADC ja Gateway -tuotteisiin useita kriittisiä haavoittuvuuksia, jotka mahdollistavat todennuksen ohittamisen, saatavuuskatkoksen taikka muun arvaamattoman toiminnan ympäristössä. Organisaatioiden tulisi asentaa valmistajan julkaisemat korjauspäivitykset viipymättä. - Haavoittuvuus: 23/2026 - Tunnisteet: CVE-2026-19489 & CVE…

  9. · CERT-FR – avis FR

    Multiples vulnérabilités dans les produits Citrix (20 août 2026)

    De multiples vulnérabilités ont été découvertes dans les produits Citrix. Elles permettent à un attaquant de provoquer un déni de service à distance, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.

  10. · Cyber Centre Kanada CA

    Citrix security advisory (AV26-833)

    Serial Number: AV26-833Date: August 19, 2026 As of August 19, 2026, NetScaler is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Version 13.1 prior to or equal to 13.1-63.21 Version 14.1 prior to or equal to 14.1-73.32 NetScaler ADC FIPS Prior to 14.1-73.32 FIPS NetScaler ADC FIPS and NDcPP Prior to 13.1-37.277 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.…

  11. · Rapid7 US

    CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway

    OverviewOn August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges.NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network…