【資安漏洞預警】NetScaler ADC與NetScaler Gateway存在高風險安全漏洞(CVE-2026-19490),請儘速確認並進行修補
【Security Vulnerability Alert】NetScaler ADC and NetScaler Gateway contain a high-risk security vulnerability (CVE-2026-19490), please promptly verify and perform patching

發布單位:圖資處網路系統組
日期範圍:2026/8/28 ~ 2027/2/28
 
發布單位:圖資處網路系統組
日期範圍:2026/8/28 ~ 2027/2/28
行政 行政公告
全體

轉發 國家資安資訊分享與分析中心 資安訊息警訊 NISAC-200-202608-00000011

[內容說明]
研究人員發現NetScaler ADC與NetScaler Gateway存在身分鑑別繞過(Authentication Bypass)漏洞(CVE-2026-19490),當設備設定為Gateway(SSL VPN、ICA Proxy、CVPN或RDP Proxy)或AAA虛擬伺服器時,未經身分鑑別之遠端攻擊者可藉由替代路徑繞過身分鑑別機制,請儘速確認並進行修補。

[影響平台]
NetScaler ADC與NetScaler Gateway 14.1-x至14.1-73.32(不含)版本
NetScaler ADC與NetScaler Gateway 13.1-x至13.1-63.21(不含)版本
NetScaler ADC FIPS 14.1-73.32(不含)以前版本
NetScaler ADC FIPS與NDcPP 13.1-37.277(不含)以前版本
使用NetScaler執行個體之Secure Private Access for Hybrid Deployments

[建議措施]
官方已針對漏洞釋出修復更新,請參考官方說明進行更新,網址如下: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939

[參考資料]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-19490
2. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939

Forwarded National Information Sharing and Analysis Center Information Security Alert NISAC-200-202608-00000011

[Content Description]
Researchers have discovered that NetScaler ADC and NetScaler Gateway contain an Authentication Bypass vulnerability (CVE-2026-19490). When devices are configured as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or an AAA virtual server, an unauthenticated remote attacker can bypass the authentication mechanism through an alternative path. Please promptly verify and perform patching.

[Impacted Platform]
NetScaler ADC and NetScaler Gateway versions 14.1-x to 14.1-73.32(excluding)
NetScaler ADC and NetScaler Gateway versions 13.1-x to 13.1-63.21(excluding)
NetScaler ADC FIPS versions prior to 14.1-73.32(excluding)
NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.277(excluding)
Secure Private Access for Hybrid Deployments using NetScaler instances

[Recommended Actions]
The official has released a security update for the vulnerability. Please refer to the official instructions for updates. The URL is as follows: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939

[Reference]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-19490
2. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939


相關附件
※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。
Top↑