< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 2 sources · 17 days · First seen · Last updated

NetScaler product security vulnerabilities

Overview

Cloud Software Group issued warnings regarding multiple critical vulnerabilities in NetScaler ADC and NetScaler Gateway products. These flaws, including CVE-2026-19490 and CVE-2026-19489, presented risks such as authentication bypass on appliances configured for SSL VPN, ICA Proxy, or RDP Proxy, as well as memory overflow issues that could lead to denial-of-service outages. Additionally, reports identified a heap-based buffer overflow (CVE-2026-8452) capable of remote code execution.

By early September, reports indicated that these vulnerabilities were being actively exploited by threat actors. The exploitation of information disclosure flaws, such as ‘CitrixBleed’ (CVE-2023-4966), allowed attackers to trigger memory leaks and extract sensitive session tokens, enabling session hijacking and the bypass of multi-factor authentication (MFA). Security agencies, including CISA and the ACSC, issued alerts urging organizations to prioritize patching and terminate active user sessions to invalidate compromised tokens.

Entities

Australian Cyber Security Centre · Citrix NetScaler Gateway · Citrix · CISA · NetScaler

Timeline

  1. 8 days ago

    [TECHNOLOGY] 2 sources
    Citrix NetScaler vulnerabilities enable session hijacking and MFA bypass

    Threat actors are exploiting critical vulnerabilities in Citrix NetScaler ADC and Gateway products to hijack sessions and bypass multi-factor authentication, prompting urgent global patching advisories.

  2. 24 days ago

    [TECHNOLOGY] 7 sources
    NetScaler faces critical vulnerabilities allowing authentication bypass

    Critical vulnerabilities in NetScaler ADC and Gateway allow for authentication bypass and remote code execution, posing severe risks to enterprise network security.

Sources

flagthis.com · thecyberexpress.com