< Back to all clusters
[TECHNOLOGY] · 7 sources

started · updated

NetScaler faces critical vulnerabilities allowing authentication bypass

Cloud Software Group has issued warnings regarding multiple critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway. These flaws, including CVE-2026-19490 and CVE-2026-19489, pose significant risks to enterprise remote access infrastructure.

One major vulnerability allows attackers to bypass authentication entirely on appliances configured for SSL VPN, ICA Proxy, or RDP Proxy, potentially granting unauthorized access to corporate networks without valid credentials. Another flaw involves a memory overflow issue that can lead to denial-of-service (DoS) outages, particularly when SIP ALG is enabled within a Large Scale NAT configuration.

Additionally, reports from watchTowr Labs highlight a heap-based buffer overflow vulnerability (CVE-2026-8452) that could lead to remote code execution when the systems are configured as SAML SP or IdP. Proof-of-concept code for deploying webshells has been released. While no active exploitation has been confirmed by JPCERT/CC as of mid-August 2026, the widespread use of these products necessitates urgent upgrades to patched versions to mitigate the risk of attack.

Entities

Cloud Software Group · JPCERT/CC · NetScaler · watchTowr Labs