SPOJENO AI KEV ✓ (1 z 2) EPSS 0.06 (nejvyšší)
Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]
Citrix SE US CA IT NL FI FR
CVE v události 2
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-19489 | 8.8 4.0 · NetScaler | – | 0.00 |
| CVE-2026-19490 | 9.3 4.0 · NetScaler | KEV ✓ | 0.06 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.3.
Jak se o tom psalo 11
-
· CERT-SE SE
Kritisk sårbarhet i Citrix NetScaler ADC och NetScaler Gateway
Citrix har publicerat information om en kritisk sårbarhet som påverkar Citrix NetScaler ADC och NetScaler Gateway. Sårbarheten, CVE-2026-19490, har fått CVSS v.4-klassning på 9.3. [1, 2]
-
· CISA KEV US
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVE-2026-19490)
CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog. Affected product: Citrix NetScaler. Remediation due date: 2026-09-12.
-
· Cyber Centre Kanada CA
AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489
Number: AL26-019Date: September 4, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre…
-
· BleepingComputer US nadpis události
Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]
-
· CERT-SE SE
Kritisk sårbarhet i Citrix NetScaler ADC och NetScaler Gateway
Citrix har publicerat information om en kritisk sårbarhet som påverkar Citrix NetScaler ADC och NetScaler Gateway. Sårbarheten, CVE-2026-19490, har fått CVSS v.4-klassning på 9.3. [1, 2]
-
· CSIRT Itálie (ACN) IT
Vulnerabilità in prodotti Citrix
Aggiornamenti di sicurezza Citrix sanano due vulnerabilità con gravità "alta" nei prodotti NetScaler ADC (precedentemente noto come Citrix ADC) e NetScaler Gateway (precedentemente noto come Citrix Gateway).
-
· NCSC-NL NL
NCSC-2026-0318 [1.00] [M/M] Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gateway
Citrix heeft kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De kwetsbaarheid met kenmerk CVE-2026-19489 betreft een memory overflow in NetScaler ADC en NetScaler Gateway, wanneer de producten zijn geconfigureerd als SIP ALG binnen een Large Scale NAT (LSN) groep. Deze fout in de geheugenallocatie kan leiden tot onvoorspelbaar gedrag of een denial of service, waardoor de normale werking van het systeem verstoord kan worden. De kwetsbaarheid met kenmerk CVE-2026-19490 maakt het…
-
· NCSC-FI FI
Citrix Netscaler ADC ja Gateway -tuotteissa kriittisiä haavoittuvuuksia
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 9.3, CVEs: CVE-2026-19489, CVE-2026-19490, Summary: Citrix on julkaissut Netscaler ADC ja Gateway -tuotteisiin useita kriittisiä haavoittuvuuksia, jotka mahdollistavat todennuksen ohittamisen, saatavuuskatkoksen taikka muun arvaamattoman toiminnan ympäristössä. Organisaatioiden tulisi asentaa valmistajan julkaisemat korjauspäivitykset viipymättä. - Haavoittuvuus: 23/2026 - Tunnisteet: CVE-2026-19489 & CVE…
-
· CERT-FR – avis FR
Multiples vulnérabilités dans les produits Citrix (20 août 2026)
De multiples vulnérabilités ont été découvertes dans les produits Citrix. Elles permettent à un attaquant de provoquer un déni de service à distance, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.
-
· Cyber Centre Kanada CA
Citrix security advisory (AV26-833)
Serial Number: AV26-833Date: August 19, 2026 As of August 19, 2026, NetScaler is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Version 13.1 prior to or equal to 13.1-63.21 Version 14.1 prior to or equal to 14.1-73.32 NetScaler ADC FIPS Prior to 14.1-73.32 FIPS NetScaler ADC FIPS and NDcPP Prior to 13.1-37.277 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.…
-
· Rapid7 US
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
OverviewOn August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges.NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network…