Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
ID: 134c1927-c20c-5a88-a4cf-dd200dff9f1a
STIX ID: report--134c1927-c20c-5a88-a4cf-dd200dff9f1a
Feed Name: The Hacker News
Threat Score
Citrix released patches for two critical NetScaler/NetScaler Gateway vulnerabilities — CVE-2026-19489 (memory overflow, CVSS 8.8) and CVE-2026-19490 (authentication bypass, CVSS 9.3) — affecting specific 13.1 and 14.1 releases and certain FIPS/NDcPP builds; CVE-19490 requires particular SAML/Gateway/AAA configurations to be exploitable and Citrix provides strings and mitigation advice (including Global Deny Lists) alongside fixed firmware versions to apply.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
