Security news

Latest security news

8 of 1,256 storiesCitrixClear all

Thu, 10 Sept 2026

  1. 2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC

    On 23 March 2026, Citrix published a security advisory addressing multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway. These vulnerabilities may lead to sensitive information disclosure and user session mix-up under specific configurations. At the time of writing, there is no public evidence of active exploitation. It is strongly recommended updating affected gateways, prioritising internet-facing assets. It is also recommended to preserve evidence for further investigation.

    CERT-EUCitrix
  2. 2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway

    On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). CERT-EU recommends updating affected devices as soon as possible.

    CERT-EUCitrix
  3. CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication

    CriticalThe Hacker NewsCitrix, Cisco, Fortinet

Wed, 9 Sept 2026

  1. AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489 - Update 1

    Number: AL26-019 Date: September 4, 2026 Updated: September 9, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre is aware of vulnerabilities impacting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) Footnote 1 . In response to the vendor advisory released on August 19, 2026, the Cyber Centre released AV26-833 on August 19, 2026 Footnote 2 . Tracked as CVE-2026-19490 Footnote 3 , this vulnerability is an Authentication Bypass Using an Alternate Path vulnerability (CWE-288) Footnote 4 . The vulnerability may allow a remote, unauthenticated attacker to circumvent authentication controls on NetScaler appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server. Tracked as CVE-2026-19489 Footnote 5

    Canadian Centre for Cyber SecurityCitrix
  2. Citrix security advisory (AV26-833) - Update 1

    Serial Number: AV26-833 Date: August 19, 2026 Updated: September 9, 2026 As of August 19, 2026, Citrix is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Version 13.1 prior to 13.1-63.21 Version 14.1 prior to 14.1-73.32 NetScaler ADC FIPS Prior to 14.1-73.32 FIPS NetScaler ADC FIPS and NDcPP Prior to 13.1-37.277 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Update 1 On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-19490 to their Known Exploited Vulnerabilities (KEV) Database. NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 Citrix Security Advisories CISA KEV: CVE-2026-19490

    Canadian Centre for Cyber SecurityCitrix

Fri, 4 Sept 2026

  1. Critical Citrix NetScaler auth bypass now leveraged in attacks

    Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian.

    BleepingComputerCitrix

Thu, 27 Aug 2026

  1. CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products

    CISA added six new bugs to its Known Exploited Vulnerabilities catalog on August 26, showing signs of active exploitation in the wild

    Infosecurity MagazineMicrosoft, Citrix, Linux

Wed, 19 Aug 2026

  1. CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway

    Overview On August 19, 2026, a security advisory was published for CVE-2026-19490 , a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges. NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network perimeter. NetScaler ADC provides application delivery, traffic management, load balancing, SSL/TLS offloading, and application security capabilities, while NetScaler Gateway provides secure remote access and VPN functionality. Because these systems are frequently deployed in enterprise DMZs and exposed to the public internet, authentication bypass vulnerabilities affecting Citrix products are nearly always exploited by threat actors. CVE-2026-19490 affects the following systems: NetScaler ADC and NetScaler Gateway 14.1: Versions prior to 14.1-73.32 NetScaler ADC and NetScaler Gateway 13.1: Versions prior to 13.1-63.21 NetScaler ADC FIPS: Versions prior to 14.1-73.32 FIPS NetScaler ADC FIPS an

    Rapid7 BlogCitrix

About this news

1,256
Stories
41
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets