TGViewer
Whitehat Lab Whitehat Lab @wh_lab · 3.17K subscribers
Post #770 1.09K
⚙️ CVE-2026-19490 - Citrix NetScaler ADC/Gateway Authentication Bypass

Критическая уязвимость в продуктах Citrix NetScaler ADC и NetScaler Gateway, которая позволяет атакующему, не прошедшему аутентификацию, обойти механизм проверки подлинности. Опасность в том, что устройства NetScaler часто располагаются на периметре сети и обеспечивают удалённый доступ, компрометация такого устройства открывает прямой путь во внутреннюю сеть

Unauthenticated session forgery on Citrix NetScaler ADC / NetScaler Gateway via the SAML HTTP-Redirect binding handler at GET /cgi/samlauth. CVSS 4.0 9.3, CWE-288. Bulletin CTX696939 (2026-08-19), no workarounds


Что делать:
Немедленно обновить все уязвимые устройства до версий 14.1-73.32 (для ветки 14.1) или 13.1-63.21 (для ветки 13.1)


🔗 Research
🐱 PoC

#cve #poc #citrix

✈️ Telegram 💬 MAX
  • 👍 3
More from @wh_lab
  1. Sep 21, 2026🔄🕸 humble v1.66 Быстрый анализатор HTTP заголовков, ориентированный на безопасность В 🐧…
  2. Sep 20, 2026🙂 Лучше вкусного напитка в пятницу может быть только вкусный напиток + доклады с OFFZONE…
  3. Sep 19, 2026💻 CVE-2026-49179: Active Directory WriteSPNScript Command Injection Компонент (ntdsai.dll…
  4. Sep 18, 2026cups2root Linux LPE Interactive root shell from a local account in the lpadmin group.
  5. Sep 18, 2026⚙️ CDP Toolkit Инструмент для работы через Chrome DevTools Protocol (CDP) Beacon Object Fi…
  6. Sep 17, 2026💀 go-responder NTLMv2 hash capture tool in pure Go zero deps, single static binary. Poiso…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →