Skip to main content

Overview

Citrix has published a security advisory alerting to multiple critical severity vulnerabilities in their NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Successful exploitation of CVE-2026-19489 could lead to a denial-of-service (DoS), and exploitation of CVE-2026-19490 could bypass authentication entirely, granting adversaries unauthorised access to the network without valid credentials when the appliance is configured as a Gateway or an AAA virtual server.

  • CVE-2026-19489 – Memory overflow vulnerability – CVSSv4.0 Score 8.8
  • CVE-2026-19490 – Authentication bypass – CVSSv4.0 Score 9.3

Affected Versions:
NetScaler ADC:

  • 1 prior to 14.1-73.32
  • 1 prior to 13.1-63.21
  • FIPS prior to 14.1-73.32 FIPS
  • FIPS and NDcPP prior to 13.1-37.277

NetScaler Gateway:

  • 1 prior to 14.1-73.32
  • 1 prior to 13.1-63.21

 

Atlassian have released patches for 162 high severity vulnerabilities across their product suite as reported in their August Security Bulletin. Exploitation of the vulnerabilities could lead to denial-of-service (DoS), remote code execution (RCE), man-in-the-middle attacks (MITM). Notable vulnerable products include Confluence, Jira and Fisheye.

Notable CVEs include:

  • CVE-2026-2332 – Fisheye – HTTP Request Smuggling – CVSSv3.1 Score 9.1
  • CVE-2021-44906 – Confluence – Prototype Pollution – CVSSv4.0 Score 9.8
  • CVE-2025-14813 – Confluence – Risky Cryptographic Algorithm – CVSSv4.0 Score 9.4
  • CVE-2026-4800 – Jira – Code Injection – CVSSv3.1 Score 9.8
  • CVE-2023-45133 – Jira – Arbitrary Code Execution – CVSSv3.1 Score 9.3



GitLab
has remediated an issue in both the community and enterprise editions which could allow an unauthenticated user to remotely modify or delete public projects and user data via the GraphQL API.

  • CVE-2026-19478 – Improper Control of Generation of Code (Code Injection) – CVSSv3.1 Score of 9.4.

Affected Versions (for both Community and Enterprise Editions):

  • All versions from 18.2 before 18.11.11
  • All versions from 19.0 before 19.0.8
  • All versions from 19.1 before 19.1.6
  • All versions from 19.2 before 19.2.4

 

Recommended Action    

Organisations are encouraged to review the appropriate security advisory pages and apply the updates:

CitrixCITRIX | Support

AtlassianAtlassian Security Bulletin for August

GitLabGitLab Critical Patch Release

Topics

  • Advisory
  • Vulnerability
  • Exploit
  • Patches and Updates