Content:
Forwarded from National Information Sharing and Analysis Center Security Alert NISAC-200-202608-00000011
Researchers have discovered an Authentication Bypass vulnerability (CVE-2026-19490) in NetScaler ADC and NetScaler Gateway. When the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or AAA Virtual Server, an unauthenticated remote attacker can bypass the authentication mechanism using an alternate path. Please verify and apply patches as soon as possible.
Affected Platforms:
NetScaler ADC and NetScaler Gateway versions 14.1-x to 14.1-73.32 (excluded)
NetScaler ADC and NetScaler Gateway versions 13.1-x to 13.1-63.21 (excluded)
NetScaler ADC FIPS versions prior to 14.1-73.32 (excluded)
NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.277 (excluded)
Secure Private Access for Hybrid Deployments using NetScaler instances
Recommendations:
References:
-
-
Computer and Communication Center
Network System Division