Tech News
← Home  ·  All topics

Citrix

3 GoKawiil briefs on this topic

Attackers exploit Citrix NetScaler auth-bypass flaw CVE-2026-19490 after PoC leak

Security researchers at Previdian and Belgium's national cyber center report that hackers are actively probing a critical authentication-bypass vulnerability in Citrix NetScaler appliances, tracked as CVE-2026-19490. The flaw affects NetScaler devices configured as AAA virtual servers or Gateways, and exploitation attempts began after a working proof-of-concept was posted online. Citrix patched the issue in mid-August but had not confirmed active exploitation as of its most recent advisory.

Citrix Adds Linux-Based UniconOS Fallback to DaaS for Broken Windows PCs

Citrix's Desktop as a Service now includes UniconOS, a lightweight, write-protected Linux environment installed alongside Windows on a separate partition. If Windows is disabled by ransomware or a bad update, employees can boot into UniconOS instead and reach their virtual apps and desktops through Citrix DaaS and SecurAccess, while Windows itself remains untouched and unrepaired.

CISA gives federal agencies until Saturday to patch Citrix NetScaler flaw CVE-2026-8452

CISA has added CVE-2026-8452, a memory overflow bug in Citrix NetScaler ADC and Gateway appliances, to its Known Exploited Vulnerabilities catalog, requiring federal civilian agencies to patch by August 29. Originally described by Citrix as only enabling denial-of-service, researchers at watchTowr later demonstrated it can be exploited for root-level remote code execution, and reports indicate attackers are already deploying web shells on unpatched systems.