Visualização normal

Ontem — 9 de Setembro de 2026Cybersecurity News
  • ✇Cybersecurity News
  • Apache Impala Vulnerabilities Expose Big Data to Remote Code Execution Do Son
    Four Apache Impala vulnerabilities expose systems to remote code execution and authentication bypass. Upgrade to Impala 4.5.2 to secure your clusters now. Related Posts: Cisco Secure Boot Bypass Details and PoC Exploit Disclosed September 2026 Android Security Bulletin Fixes Critical System RCE Flaws CVE-2026-84372 PoC Disclosed: Predis Command Injection Flaw The post Apache Impala Vulnerabilities Expose Big Data to Remote Code Execution appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Critical Siemens Vulnerabilities Hit Industrial Edge and OIS Do Son
    Two critical Siemens vulnerabilities (CVE-2026-18963, CVE-2026-50093) allow account takeover and root access. See affected versions and fixes. Related Posts: Cisco Secure Boot Bypass Details and PoC Exploit Disclosed September 2026 Android Security Bulletin Fixes Critical System RCE Flaws Apache Impala Vulnerabilities Expose Big Data to Remote Code Execution The post Critical Siemens Vulnerabilities Hit Industrial Edge and OIS appeared first on Daily CyberSecurity.
     
Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • MikroTrick PoC: RouterOS Admin Rights Exploited In Wild Do Son
    The MikroTrick PoC is publicly disclosed. This MikroTrick RouterOS flaw is actively exploited in the wild, granting full administrative privileges. Related Posts: CVE-2026-86218 (CVSS 10): N-central Pre-Auth RCE Exploited in the Wild AI Agent Coordination: The Unprecedented OpenAI Breakout Roundcube Security Update Fixes 12 Webmail Flaws The post MikroTrick PoC: RouterOS Admin Rights Exploited In Wild appeared first on Daily CyberSecurity.
     
  • ✇Firewall Daily – The Cyber Express
  • Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk Samiksha Jain
    Two Citrix NetScaler vulnerabilities affecting Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products have prompted a patching warning for Australian organisations. The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has advised organisations using the products to assess their environments and apply available security updates as a priority. Citrix has identified two vulnerabilities affecting NetScaler ADC and NetScaler Gatew
     

Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk

4 de Setembro de 2026, 03:21

Citrix NetScaler vulnerabilities

Two Citrix NetScaler vulnerabilities affecting Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products have prompted a patching warning for Australian organisations. The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has advised organisations using the products to assess their environments and apply available security updates as a priority. Citrix has identified two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, which are critical edge devices used in enterprise networking to securely deliver applications, data and remote access to users.

Citrix NetScaler Vulnerabilities Affect ADC and Gateway

The first flaw, CVE-2026-19489, is a memory overflow vulnerability. According to the alert, exploitation of this vulnerability requires SIP ALG, or Session Initiation Protocol Application Layer Gateway, to be enabled on a Large Scale NAT (LSN) group configuration. The second flaw, CVE-2026-19490, is an authentication bypass vulnerability. The vulnerability requires SAML actions to be enabled and/or the affected product to be configured as a VPN gateway. The conditions required for each vulnerability mean that organisations need to assess their specific Citrix configurations to determine whether affected systems are present in their environments.

Patches Released for Citrix NetScaler products

Citrix released patches for the affected products on August 19, 2026. ASD's ACSC is urging organisations to review the vendor's mitigation guidance, identify vulnerable versions of Citrix products and update affected systems to the latest versions. The advisory places particular emphasis on timely patching because critical edge devices are frequently targeted by threat actors as an entry point into sensitive environments. However, ASD's ACSC said it has no information indicating that a specific Australian industry or sector is currently being targeted in connection with these vulnerabilities.

Organisations Urged to Assess Vulnerable Versions

The mitigation guidance calls on organisations to assess their networks and environments for vulnerable versions of Citrix products and apply patches as soon as practicable. Organisations should also review the mitigation advice provided by Citrix and confirm that affected systems have been updated. Where NetScaler ADC and NetScaler Gateway products are managed by a third party, organisations are advised to contact the relevant managed service provider (MSP) or enterprise IT provider. They should confirm that the products have been patched and are being monitored for suspicious activity. This step is particularly relevant for organisations that do not directly manage their Citrix infrastructure and may rely on external providers for patching and monitoring.

Monitoring Remains Important After Patching

Alongside addressing the Citrix NetScaler vulnerabilities, organisations are advised to monitor affected environments for suspicious activity. The alert recommends notifying ASD's ACSC if suspicious activity is detected. The two vulnerabilities affect different configurations, with CVE-2026-19489 requiring SIP ALG to be enabled on an LSN group configuration, while CVE-2026-19490 requires SAML actions to be enabled and/or the product to be configured as a VPN gateway. For Australian organisations using Citrix NetScaler products, the immediate steps outlined by ASD's ACSC are to identify vulnerable versions, apply the available patches, confirm third-party-managed systems have been addressed and maintain monitoring for suspicious activity.
  • ✇Cybersecurity News
  • FreeRDP 3.31.0 Fixes Pre-Auth RCE Chain in Server Do Son
    FreeRDP 3.31.0 patches 5 server-role flaws, including a pre-auth remote code execution chain affecting GNOME Remote Desktop and KDE krdp. Related Posts: Critical Google Chrome Vulnerabilities Patched in New Update CVE-2026-80047: Hugging Face Transformers Library Vulnerability CVE-2026-68162: Linux Kernel Root Escalation PoC Public The post FreeRDP 3.31.0 Fixes Pre-Auth RCE Chain in Server appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Proxmox VE 7 Auth Bypass: PoC Public, Exploited in the Wild Do Son
    A public PoC now targets a Proxmox VE authentication bypass in EOL 7.x releases, and the pre-auth flaw is exploited in the wild for root access. Related Posts: Critical Google Chrome Vulnerabilities Patched in New Update CVE-2026-80047: Hugging Face Transformers Library Vulnerability CVE-2026-68162: Linux Kernel Root Escalation PoC Public The post Proxmox VE 7 Auth Bypass: PoC Public, Exploited in the Wild appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover Do Son
    A critical Artifactory authentication bypass flaw (CVE-2026-82329) is exploited in the wild, letting attackers obtain administrative privileges. Related Posts: CVE-2026-81934: Redis RCE PoC Exploit Now Public CVE-2026-78319: SAUTER Controller RCE Flaw Disclosed Cosmos EVM Flaw Triggers Multi-Chain Heist The post CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update Do Son
    Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now. Related Posts: GitLab Updates Fix Arbitrary Command Execution Vulnerability FreeBSD Patches Eight Kernel Vulnerabilities UniFi CVE-2026-77537 (CVSS 10.0): Command Injection Flaws Hit 22 Ubiquiti Products The post Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Ebyte NE2-D11 Gateway Hit by 11 Vulnerabilities, No Patch Yet Do Son
    CISA warns of 11 Ebyte NE2-D11 vulnerabilities, four rated 9.8, that allow full device takeover. No patch is confirmed available yet. Related Posts: GitLab Updates Fix Arbitrary Command Execution Vulnerability FreeBSD Patches Eight Kernel Vulnerabilities UniFi CVE-2026-77537 (CVSS 10.0): Command Injection Flaws Hit 22 Ubiquiti Products The post Ebyte NE2-D11 Gateway Hit by 11 Vulnerabilities, No Patch Yet appeared first on Daily CyberSecurity.
     
❌
❌