started · updated
Citrix NetScaler vulnerabilities enable session hijacking and MFA bypass
Critical vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway products are being actively exploited by threat actors. The flaws, including the information disclosure vulnerability known as ‘CitrixBleed’ (CVE-2023-4966), allow attackers to trigger memory leaks and extract sensitive session tokens. This enables session hijacking and the ability to bypass multi-factor authentication (MFA), providing a primary entry point for lateral movement and ransomware deployment.
Additional vulnerabilities, such as CVE-2026-19489 and CVE-2026-19490, involve memory overflow and authentication bypass risks depending on specific configurations like SIP ALG or SAML settings. Security agencies, including the Cybersecurity and Infrastructure Security Agency (CISA) and the Australian Cyber Security Centre (ACSC), have issued alerts urging organizations to prioritize patching and assess their environments.
To mitigate these risks, experts recommend applying vendor security patches immediately and terminating all active user sessions to invalidate potentially compromised tokens.
Entities
Australian Cyber Security Centre · CISA · Citrix · Citrix NetScaler ADC · Citrix NetScaler Gateway