Start your day with intelligence. Get The OODA Daily Pulse.
Citrix patches critical NetScaler authentication bypass.
Citrix released fixes for a critical authentication bypass in NetScaler ADC and Gateway that allows remote, unauthenticated access to appliances configured as gateways or AAA virtual servers. The flaw, CVE‑2026‑19490, affects multiple 14.1 and 13.1 builds, alongside a separate high‑severity memory overflow issue tied to SIP ALG. Rapid7 says no exploitation has been observed yet but warns that NetScaler’s perimeter role makes the bug a high‑value target likely to see attacks soon. Agencies urge emergency patching, noting that unpatched systems could enable attackers to modify traffic, disrupt operations, or gain unauthorized remote access.
Read more: