Critical

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

Help Net Security

Overview

Citrix has identified and patched two vulnerabilities in its NetScaler ADC and NetScaler Gateway products, one of which is a serious authentication bypass flaw designated as CVE-2026-19490. This vulnerability could allow unauthorized access to systems, putting customer data at risk. Citrix is urging all users of the affected appliances to check if their deployments are impacted and to promptly upgrade to the recommended builds. Anil Shetty, a senior VP at Cloud Software Group, emphasized the importance of this upgrade to maintain security. Users need to act quickly to prevent potential exploitation of this flaw.

Key Takeaways

  • Affected Systems: NetScaler ADC, NetScaler Gateway, Citrix products
  • Action Required: Customers should upgrade their affected appliances to the recommended builds as outlined in the official NetScaler ADC and NetScaler Gateway security bulletin.
  • Timeline: Newly disclosed

Original Article Summary

Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible. “We strongly recommend that customers review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,” Anil Shetty, senior VP of Engineering with Cloud Software Group … More → The post Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) appeared first on Help Net Security.

Impact

NetScaler ADC, NetScaler Gateway, Citrix products

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Newly disclosed

Remediation

Customers should upgrade their affected appliances to the recommended builds as outlined in the official NetScaler ADC and NetScaler Gateway security bulletin.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, Critical.

Related Coverage

Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown

Security Affairs

Despite a recent takedown of its command-and-control servers, the WeedHack malware is still being distributed through fake Minecraft client websites. McAfee Labs reported that there are currently ten active malicious sites, along with several file-hosting accounts, that continue to spread this infostealer. The attackers are using SEO poisoning techniques to ensure these harmful downloads appear at the top of Google search results, making it easier for unsuspecting users to find them. This ongoing campaign puts Minecraft players at risk, as they may unknowingly download software that compromises their personal information and gaming accounts. The persistence of these sites even after efforts to disrupt the malware's infrastructure underscores the need for users to be vigilant about where they download software from.

Aug 25, 2026

AI supply chain risk is showing up in developer workflows first

Help Net Security

In a recent interview, Dr. Jaushin Lee, CEO of Zentera Systems, pointed out that AI supply chain risks are primarily affecting developer workflows and open-source package repositories. He noted that while some issues like poisoned model weights and compromised servers are mainly seen in research settings, the real-world impact is felt in the everyday work of developers. Dr. Lee emphasized that companies might gain more risk reduction from proper segmentation of their systems than from investing heavily in new tools. He also mentioned the shortcomings of self-hosting AI models and suggested that software teams could benefit by adopting certain semiconductor isolation practices. This conversation brings attention to the evolving risks in AI development and the need for better security practices in software development environments.

Aug 25, 2026

New TCG guidance gives buyers a way to test PQC-ready TPM claims

Help Net Security

The Trusted Computing Group (TCG) has released new guidelines for Trusted Platform Modules (TPMs), which are essential components that secure a device's cryptographic keys and firmware integrity. These guidelines specifically address how TPMs can be deemed quantum-safe, a growing concern as quantum computing technology advances. Now, buyers can request proof from vendors that their TPMs meet these new standards, ensuring they are prepared for future quantum threats. This is significant for companies looking to protect their data from potential quantum attacks, as it provides a way to verify the security claims made by manufacturers. The move aims to enhance the overall security landscape as businesses transition to quantum-resistant technology.

Aug 25, 2026

ShinyHunters claims social engineering attack against ReliaQuest

SCM feed for Latest

A group known as ShinyHunters claims to have executed a social engineering attack against ReliaQuest. The attackers targeted employees by calling them and attempting to deceive them into visiting a fraudulent single sign-on (SSO) page. This fake page was hosted on a lookalike domain, reliaquest[.]claims, designed to mimic the legitimate ReliaQuest site. Such tactics can lead to credential theft and unauthorized access to sensitive company data. This incident raises concerns about the effectiveness of security training and awareness among employees, as social engineering remains a prevalent threat in cybersecurity.

Aug 24, 2026

WordPress plugin vulnerabilities allow admin account takeover

SCM feed for Latest

Researchers have identified two vulnerabilities in WordPress plugins, tracked as CVE-2026-61979 and CVE-2026-15981, that can be exploited together to bypass authentication and potentially take over admin accounts. This poses a significant risk to users of affected plugins, as attackers could gain unauthorized access to sensitive areas of WordPress sites. The vulnerabilities are particularly concerning for website administrators who may not be aware of these security flaws. It's crucial for users to check if their plugins are affected and take appropriate action to secure their sites, especially since the potential for exploitation exists. Prompt updates and vigilance are key to maintaining site security in light of these findings.

Aug 24, 2026

Developer alleges Alibaba uses audio fingerprinting for web tracking

SCM feed for Latest

Matt Callaghan, a software engineer, has raised concerns that Alibaba's website may be using audio fingerprinting techniques for tracking users. He found that the site employs obfuscated audio scripts that create a waveform and analyze its output, which could allow the company to monitor user behavior in a way that bypasses traditional tracking methods. This discovery raises significant privacy issues, as it suggests that users may be unwittingly tracked through audio signals emitted from their devices. The implications are serious, especially for individuals who value their privacy online. The use of such techniques could lead to increased scrutiny from regulators and may prompt users to reconsider their interactions with the site.

Aug 24, 2026