# NetScaler product security vulnerabilities

> Live situation record from CLSTR: https://clstr.news/situations/netscaler-product-security-vulnerabilities
> Updated: 2026-09-04T06:21:44.000Z. Sources: 2. Developments: 2.

Cloud Software Group issued warnings regarding multiple critical vulnerabilities in NetScaler ADC and NetScaler Gateway products. These flaws, including CVE-2026-19490 and CVE-2026-19489, presented risks such as authentication bypass on appliances configured for SSL VPN, ICA Proxy, or RDP Proxy, as well as memory overflow issues that could lead to denial-of-service outages. Additionally, reports identified a heap-based buffer overflow (CVE-2026-8452) capable of remote code execution.

By early September, reports indicated that these vulnerabilities were being actively exploited by threat actors. The exploitation of information disclosure flaws, such as ‘CitrixBleed’ (CVE-2023-4966), allowed attackers to trigger memory leaks and extract sensitive session tokens, enabling session hijacking and the bypass of multi-factor authentication (MFA). Security agencies, including CISA and the ACSC, issued alerts urging organizations to prioritize patching and terminate active user sessions to invalidate compromised tokens.

## Timeline

### 2026-09-04: Citrix NetScaler vulnerabilities enable session hijacking and MFA bypass

Threat actors are exploiting critical vulnerabilities in Citrix NetScaler ADC and Gateway products to hijack sessions and bypass multi-factor authentication, prompting urgent global patching advisories.

2 sources. https://clstr.news/cluster/citrix-netscaler-vulnerabilities-enable-session-hijacking-and-mfa-bypass

### 2026-08-18: NetScaler faces critical vulnerabilities allowing authentication bypass

Critical vulnerabilities in NetScaler ADC and Gateway allow for authentication bypass and remote code execution, posing severe risks to enterprise network security.

7 sources. https://clstr.news/cluster/netscaler-faces-critical-vulnerabilities-allowing-authentication-bypass

---
Cite as: NetScaler product security vulnerabilities. CLSTR, https://clstr.news/situations/netscaler-product-security-vulnerabilities
