轉發 國家資安資訊分享與分析中心 資安訊息警訊 NISAC-200-202608-00000011
[內容說明]
研究人員發現NetScaler ADC與NetScaler Gateway存在身分鑑別繞過(Authentication Bypass)漏洞(CVE-2026-19490),當設備設定為Gateway(SSL VPN、ICA Proxy、CVPN或RDP Proxy)或AAA虛擬伺服器時,未經身分鑑別之遠端攻擊者可藉由替代路徑繞過身分鑑別機制,請儘速確認並進行修補。
[影響平台]
NetScaler ADC與NetScaler Gateway 14.1-x至14.1-73.32(不含)版本
NetScaler ADC與NetScaler Gateway 13.1-x至13.1-63.21(不含)版本
NetScaler ADC FIPS 14.1-73.32(不含)以前版本
NetScaler ADC FIPS與NDcPP 13.1-37.277(不含)以前版本
使用NetScaler執行個體之Secure Private Access for Hybrid Deployments
[建議措施]
官方已針對漏洞釋出修復更新,請參考官方說明進行更新,網址如下: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939
[參考資料]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-19490
2. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939
Forwarded National Information Sharing and Analysis Center Information Security Alert NISAC-200-202608-00000011
[Content Description]
Researchers have discovered that NetScaler ADC and NetScaler Gateway contain an Authentication Bypass vulnerability (CVE-2026-19490). When devices are configured as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or an AAA virtual server, an unauthenticated remote attacker can bypass the authentication mechanism through an alternative path. Please promptly verify and perform patching.
[Impacted Platform]
NetScaler ADC and NetScaler Gateway versions 14.1-x to 14.1-73.32(excluding)
NetScaler ADC and NetScaler Gateway versions 13.1-x to 13.1-63.21(excluding)
NetScaler ADC FIPS versions prior to 14.1-73.32(excluding)
NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.277(excluding)
Secure Private Access for Hybrid Deployments using NetScaler instances
[Recommended Actions]
The official has released a security update for the vulnerability. Please refer to the official instructions for updates. The URL is as follows: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939
[Reference]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-19490
2. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939