Exploited Vulnerabilities Daily
🌐 繁體中文

← 所有新增項目

CVE-2026-19490: Citrix NetScaler

Citrix Net Scaler ADC 和 NetScaler Gateway 包含一個包含一個替代路徑或通道的認證-透過漏洞。當Netscaler應用程式配置為AAA虛擬伺服器或Gateway(SSL VPN,ICA Proxy,CVPN,或RDP Proxy)時,一個未經認證的遠端威脅演員可能可以繞過認證。

CISA (English)

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.

廠商
Citrix
產品
NetScaler
漏洞
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
加入日期
2026年9月9日
CISA 修補期限(美國聯邦機關)
2026年9月12日
已知用於勒索軟體攻擊
未知
弱點(CWE)
CWE-288

參考資料

本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。

最後更新: · 目錄版本 2026.10.02