Critical Authentication Bypass and Buffer Overflow Flaws Patched in NetScaler ADC and Gateway
Cloud Software Group has released a security advisory detailing two severe vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). The issues are rated Critical, the highest severity level, prompting immediate calls for customers to apply updates.
CVE-2026-19490 allows attackers to bypass authentication by leveraging an alternate path. The flaw affects environments where the products function as SSL VPN, ICA proxy, CVPN, or RDP proxy gateways, as well as when configured as authentication, authorization, and auditing virtual servers. In certain builds, the presence of a configured SAML action is also a prerequisite for exploitation.
CVE-2026-19489 is a buffer overflow vulnerability that manifests when SIP ALG is enabled within an LSN group. Successful exploitation may result in unexpected behavior or a denial-of-service condition.
The CVSS v4.0 base scores are 9.3 for CVE-2026-19490 and 8.8 for CVE-2026-19489. The advisory contains no information indicating that the vulnerabilities have been exploited in the wild.
Patches are available in builds 14.1-73.32 and 13.1-63.21. Corresponding updates for FIPS and NDcPP editions have also been released, and administrators are strongly advised to upgrade without delay.
Related articles
Apple Releases macOS Updates to Fix CoreGraphics Vulnerability Possibly Exploited in Targeted iOS Attacks
Apple has issued security updates for multiple macOS versions to address a serious vulnerability in the CoreGraphics framework. The flaw, tracked as CVE-2026-86950, involves an out-of-bounds write that could allow arbitrary code execution when processing specially crafted files. The company also noted that the same issue may have been exploited in sophisticated, targeted attacks against older versions of iOS. CISA assigned the vulnerability a CVSS v3.1 base score of 8.8, classifying it as High severity. Patches are now available in macOS Tahoe 26.7.1, macOS Sequoia 15.8.1, and the latest macOS Golden Gate 27.0.1 release.
Apple Releases iOS 26.7.1 and iPadOS 26.7.1 to Fix CoreGraphics Vulnerability Possibly Exploited in Targeted Attacks
Apple has issued iOS 26.7.1 and iPadOS 26.7.1 to address a high-severity vulnerability in the CoreGraphics framework. The flaw, tracked as CVE-2026-86950, could allow arbitrary code execution when processing a specially crafted file due to an out-of-bounds write. The company stated that the issue may have been exploited in sophisticated, targeted attacks against specific individuals on versions prior to iOS 27. CISA assigned the vulnerability a CVSS v3.1 base score of 8.8, classifying it as High severity. On the same day, Apple also released iOS 27.0.1 and iPadOS 27.0.1, though those updates did not reference CVE-2026-86950. The patches close a vector that could be abused for remote code execution in image rendering components.
Fundamental Flaw in File Monitoring APIs Exposes Keystrokes and App Activity Across Windows, Linux, Android, and macOS
Researchers from Graz University of Technology demonstrated how built-in file change notification mechanisms can leak sensitive user activity without requiring elevated privileges. The affected subsystems include inotify on Linux, FileObserver on Android, ReadDirectoryChangesW on Windows, and FSEvents on macOS. On Linux the technique enables reconstruction of typed text with 93-100% accuracy by monitoring /dev/input/event4 timestamps. Android apps can break sandbox isolation to observe messaging events, while Windows monitoring of browser cache files reveals visited websites at 97.8% accuracy. Only partial mitigations have been deployed in Linux and Windows, with no fixes available for Android or macOS. Additional attacks remain possible, including detection of password prompts to facilitate phishing overlays.
16-Year-Old Researcher Discovers Authentication Bypass in Microsoft Titan Analytics Platform
A 16-year-old security researcher using the pseudonym Faav identified a critical flaw in Microsoft Titan, the company's internal analytics platform. The vulnerability allowed an attacker to submit forged JSON Web Tokens that bypassed signature verification and granted administrator privileges. With these rights, the researcher could execute arbitrary SQL queries against connected databases containing metadata from nearly 10,000 tables. Microsoft received the report on September 5, disabled public API access four days later, and issued a $5,000 bounty on September 17. No evidence has emerged that the issue was exploited by malicious actors before remediation. The researcher accessed only limited metadata and a small number of records during testing and did not exfiltrate customer personal data.