Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Seventeen-year-old girl killed in sword attack at school in Sweden | Sweden

    August 22, 2026

    An okay laptop with 16GB of RAM is better than a nice laptop with 8GB, and this $520 HP OmniBook proves it

    August 22, 2026

    Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

    August 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Seventeen-year-old girl killed in sword attack at school in Sweden | Sweden
    • An okay laptop with 16GB of RAM is better than a nice laptop with 8GB, and this $520 HP OmniBook proves it
    • Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
    • This frozen fiber makes light and sound interact 1,000x more strongly
    • 10 COVID-19 vaccine claims we’ve investigated during Trump’s 2nd term
    • Carney Slams U.S.-Canada Trade Proposal and Vows Retaliation
    • Nancy Kassebaum, First Woman to Chair a Major Senate Panel, Dies at 94
    • W. Kamau Bell has the most practical ‘most indispensable tool’
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 22
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 22, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 20, 2026Network Security / Enterprise Security

    Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability.

    According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess ZTNA Hybrid deployments that use customer-managed NetScaler instances.

    It bears noting that the vulnerabilities do not apply to Citrix-managed cloud services or Citrix-managed Adaptive Authentication, as the necessary updates have already been applied. The list of impacted NetScaler versions is below –

    • NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-73.32
    • NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.21
    • NetScaler ADC FIPS BEFORE 14.1-73.32 FIPS
    • NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.277

    The first of the two vulnerabilities is CVE-2026-19489 (CVSS score: 8.8), a memory overflow vulnerability that may lead to unpredictable behavior or denial-of-service (DoS). However, it applies only when Session Initiation Protocol Application Layer Gateway (SIP ALG) is enabled on a Large Scale NAT (LSN) group configuration.

    Cybersecurity

    CVE-2026-19490 (CVSS score: 9.3), the more severe of the two, is an authentication bypass vulnerability that affects appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, assuming the following version-specific requirements are met –

    • 14.1-43.56 or later – Applicable only when configured with a SAML action AND NetScaler is configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver
    • 14.1-66.68-FIPS or later – Applicable only when configured with a SAML action AND NetScaler is configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver
    • 14.1-43.55 or earlier – Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy ) or AAA vserver
    • 13.1-61.28 or later – Applicable only when configured with a SAML action
    • 13.1-61.27 or earlier – Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver
    • 13.1 FIPS – Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver

    “Customers should also review their configurations to determine whether the documented preconditions apply,” Citrix said. “Prioritization should be based on exposure, deployment role, and whether the affected configuration is enabled.”

    For CVE-2026-19489, customers can check if their device meets the precondition by inspecting their NetScaler configuration for the specified string –

    Similarly, for CVE-2026-19490, customers can verify their NetScaler configuration for the below string –

    • add authentication samlAction.* (SAML action configuration)
    • add authentication vserver .* or add vpn vserver .* (for AAA or VPN vserver)

    “Additionally, this vulnerability can be mitigated by using signatures if you are using NetScaler Console (Service or on-prem) and if the NetScaler firmware version is higher than 14.1-60.52 and 13.1-63.16 or higher, which have a feature called Global Deny Lists that consumes the signatures and automatically applies the signatures to NetScaler appliances managed via NetScaler Console,” Citrix said. “The feature is enabled by default.”

    Cybersecurity

    The updates are available in the following versions –

    • NetScaler ADC and NetScaler Gateway 14.1-73.32 or later
    • NetScaler ADC and NetScaler Gateway 13.1-63.21 or later
    • NetScaler ADC FIPS 14.1-73.32 FIPS or later
    • NetScaler ADC FIPS and NDcPP 13.1-37.277 or later

    Citrix has credited Samarth Vashisht from the pen-test team at JPMorgan Chase for discovering and reporting the flaws. Although there is no evidence that the shortcomings have been exploited in the wild, newly disclosed Citrix vulnerabilities have been a lucrative target for attackers.

    Last month, an insufficient input validation vulnerability in NetScaler ADC and NetScaler Gateway (CVE-2026-8451, CVSS score: 8.8) witnessed active exploitation efforts less than 24 hours of public disclosure.

    AAA Authentication Bypass critical Flaw gateway NetScaler Servers
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

    Named Pipes Under Attack: Securing Windows Interprocess Communication

    Hackers infect Android car head units with proxy botnet malware

    Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

    Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution

    Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Seventeen-year-old girl killed in sword attack at school in Sweden | Sweden

    August 22, 2026

    An okay laptop with 16GB of RAM is better than a nice laptop with 8GB, and this $520 HP OmniBook proves it

    August 22, 2026

    Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

    August 22, 2026

    This frozen fiber makes light and sound interact 1,000x more strongly

    August 22, 2026
    Latest Posts

    Satirical fake Guardian front page on ‘genetic links’ between eating bacon and far-right activism shared as genuine – Full Fact

    July 28, 2026

    U.S. Foreign Policy Must Prioritize Human Rights

    July 28, 2026

    Madison revisits police body cameras after years of debate

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Seventeen-year-old girl killed in sword attack at school in Sweden | Sweden

    August 22, 2026

    An okay laptop with 16GB of RAM is better than a nice laptop with 8GB, and this $520 HP OmniBook proves it

    August 22, 2026

    Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

    August 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.