New firewall and VPN vulnerabilities in Cisco, Citrix and Fortinet gear are under active attack. A step-by-step checklist for IT managers without a dedicated security team.
Tag:
Citrix
-
-
Citrix called CVE-2026-8452 a memory overflow. It turned out to be an unauthenticated root exploit, and that gap says something about how patch priority gets set.
-
The critical NetScaler authentication bypass, CVE-2026-19490, was routine to fix. The pattern behind it, of gateway appliances patched on a normal cycle, is the real risk.