<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Citrix on PhllapsNET</title>
    <link>https://www.phllaps.net/tags/citrix/</link>
    <description>Recent content in Citrix on PhllapsNET</description>
    <generator>Hugo</generator>
    <language>en-gb</language>
    <lastBuildDate>Wed, 09 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://www.phllaps.net/tags/citrix/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability</title>
      <link>https://www.phllaps.net/posts/citrix-netscaler-authentication-bypass-using-an-alternate-path-or-channel-vulnerability/</link>
      <pubDate>Wed, 09 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/citrix-netscaler-authentication-bypass-using-an-alternate-path-or-channel-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.8&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.8 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-09-09) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Fixed in &lt;code&gt;13.1-37.277&lt;/code&gt;, &lt;code&gt;13.1-63.21&lt;/code&gt;, &lt;code&gt;14.1-73.32&lt;/code&gt;&lt;/strong&gt; — upgrade to this release or later.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-19490.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-19490 is an authentication bypass in Citrix NetScaler ADC and NetScaler Gateway. The flaw sits in how the appliance validates identity when it has been configured as an AAA virtual server, or as a Gateway serving SSL VPN, ICA Proxy, CVPN, or RDP Proxy. Citrix describes it as bypass via an alternate path or channel — the login route intended to enforce authentication can be circumvented.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
