CVE-2026-19490: Critical Citrix NetScaler Authentication Bypass Exposes Enterprise Gateways

Cloud Software Group has released critical security updates to address CVE-2026-19490, an authentication bypass vulnerability (CWE-288) in NetScaler ADC and NetScaler Gateway rated 9.3 on the CVSS v4.0 scale. This flaw allows unauthenticated remote attackers to circumvent authentication controls on appliances configured as gateways—including SSL VPN, ICA Proxy, Clientless VPN, and RDP Proxy—or as AAA virtual servers. For NetScaler versions 14.1-43.56 (and later vulnerable builds) and 13.1-61.28 (and later vulnerable builds), exploitation requires a configured SAML action, whereas older builds (14.1-43.55 and earlier, and 13.1-61.27 and earlier) are vulnerable simply by operating as a Gateway or AAA virtual server. The vulnerability affects NetScaler ADC and Gateway versions 14.1 prior to 14.1-73.32 and 13.1 prior to 13.1-63.21, including corresponding FIPS and NDcPP releases, as well as Secure Private Access Hybrid deployments relying on customer-managed instances. To mitigate this threat, administrators must immediately upgrade affected customer-managed appliances to versions 14.1-73.32, 13.1-63.21, or later, and monitor authentication telemetry for anomalies such as successful sessions lacking corresponding login events, unusual SAML-related requests, or unexpected configuration modifications.

Severity: Critical

Threat Details and IOCs

CVEs: CVE-2026-19489, CVE-2026-19490, CVE-2026-3055, CVE-2026-4368
Technologies: Citrix NetScaler ADC, Citrix NetScaler Gateway, NetScaler ADC, NetScaler Gateway
Victim Industries: Education, Financial Services, Government, Healthcare, Manufacturing, Retail, Telecommunications
Victim Countries: United States

Mitigation Advice

  • Upgrade all vulnerable NetScaler ADC and Gateway 14.1 instances to version 14.1-73.32 or later.
  • Upgrade all vulnerable NetScaler ADC and Gateway 13.1 instances to version 13.1-63.21 or later.
  • Create an inventory of all NetScaler ADC and Gateway appliances, noting their software versions, network locations, and whether they are internet-facing.
  • Archive all NetScaler authentication, access, and VPN logs from at least the last 90 days before performing upgrades.
  • In your SIEM, search NetScaler and VPN logs for successful access sessions that do not have a corresponding successful user authentication event immediately preceding them.
  • Analyze VPN and remote access logs for successful connections from geographic locations or IP address ranges not associated with your business or remote workforce.
  • Inspect the configurations of all NetScaler appliances to identify any configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server.
  • Inspect the configurations of all NetScaler appliances to identify any that have a SAML action configured.

Compliance Best Practices

  • Implement an automated asset discovery and management program to maintain a continuous inventory of all network edge devices and their software versions.
  • Develop and formalize an emergency vulnerability management policy that defines specific procedures and timelines for patching critical vulnerabilities on internet-facing systems outside of the normal patch cycle.
  • Develop and deploy SIEM detection rules to automatically alert on suspicious NetScaler activities, such as successful sessions without a corresponding authentication event or access from unexpected geolocations.
  • Ensure all NetScaler appliances are configured to forward comprehensive authentication, VPN, and configuration logs to a centralized SIEM and that these logs are retained for at least one year.
  • Establish a technology lifecycle management policy that mandates the replacement or upgrade of all hardware and software before they reach end-of-support.
  • Enforce multi-factor authentication (MFA) on all critical applications and services accessed via the NetScaler Gateway to provide an additional layer of security.
  • Review and strengthen network segmentation rules to restrict traffic from the VPN/remote access zone to only the specific internal resources required by remote users.

CVE-2026-76310: Critical Access Control Flaw in Splunk Enterprise Exposes Session Material

A critical improper access control vulnerability, tracked as CVE-2026-76310 with a CVSS v3.1 score of 9.4, affects the embedded reporting functionality of Splunk Enterprise. The vulnerability arises because the REST API endpoint responsible for delivering embedded report results does not restrict requests to download the search job's dispatch archive. Consequently, an unauthenticated network attacker possessing only an embedded report token can retrieve this archive, which contains session material that can be used to impersonate the report's owner and potentially execute administrative actions if the owner holds admin privileges. This vulnerability affects Splunk Enterprise versions 10.4 (prior to 10.4.2), 10.2 (prior to 10.2.6), 10.0 (prior to 10.0.9), and 9.4 (prior to 9.4.14). While there is currently no active exploitation or public proof of concept, organizations are advised to upgrade to patched versions (10.4.2, 10.2.6, 10.0.9, and 9.4.14 or higher) or apply a temporary workaround by disabling global report embedding via setting `allowEmbedTokenAuth = false` in the `server.conf` configuration file.

Severity: Critical

Threat Details and IOCs

CVEs: CVE-2026-76253, CVE-2026-76259, CVE-2026-76310, CVE-2026-76311, CVE-2026-76312, CVE-2026-76313, CVE-2026-76314, CVE-2026-76315, CVE-2026-76338, CVE-2026-76352
Technologies: Splunk
Victim Industries: Healthcare
Victim Countries: France

Mitigation Advice

  • Perform a network-wide scan to identify all Splunk Enterprise instances and document their specific versions to determine which are vulnerable to CVE-2026-76310.
  • On all identified vulnerable Splunk instances that do not use the embedded reports feature, immediately apply the recommended workaround by setting 'allowEmbedTokenAuth = false' in the server.conf file.
  • Prioritize and apply the security patches to all vulnerable Splunk Enterprise instances, upgrading them to the versions specified in the advisory (10.4.2, 10.2.6, 10.0.9, 9.4.14, or higher).

Compliance Best Practices

  • Conduct a comprehensive review of all Splunk user roles and permissions to enforce the principle of least privilege. Ensure that service accounts or user accounts responsible for generating reports do not have administrative rights.
  • Implement and maintain a comprehensive software asset management inventory that includes application owners, versions, and patch status to enable rapid identification of systems affected by future vulnerabilities.
  • Review and enhance network segmentation rules to restrict access to the Splunk web interface and REST API endpoints, ensuring they are only accessible from trusted administrative subnets or via a secure management bastion.
  • Develop and implement a formal vulnerability management policy that defines timelines and procedures for patching systems based on severity, with specific, aggressive SLAs for critical vulnerabilities like CVE-2026-76310.

Cruciferra Malware Leverages MocoMsys Driver to Bypass Endpoint Security, Targeting Microsoft Defender

In late July 2026, threat actors began leveraging the ErrTraffic malware-as-a-service platform, operated by an actor known as LenAI, to execute ClickFix social engineering campaigns that deliver the Cruciferra malware loader. The infection chain begins on compromised WordPress sites where an obfuscated JavaScript implant queries a Polygon smart contract to resolve active command-and-control domains and serve fake Google reCAPTCHA, Cloudflare Turnstile, or Windows Blue Screen of Death pages. These lures trick users into copying a malicious PowerShell command to their clipboard and manually executing it, bypassing traditional download controls. Once executed, Cruciferra utilizes DLL side-loading via a malicious `mscoree.dll` and process hollowing to inject the Remus information stealer into `ServiceModelReg.exe`. To evade detection, Cruciferra executes a Bring Your Own Vulnerable Driver (BYOVD) attack by exploiting a User Account Control bypass, dropping the signed-but-vulnerable MocoMsys driver `DCRCVDrv.sys` into `C:\Windows\Temp\`, and registering it as a service. This driver exposes an IOCTL that allows the malware to terminate 145 antivirus and endpoint detection and response (EDR) processes, including Microsoft Defender, CrowdStrike Falcon, and SentinelOne. Defenders can mitigate this threat by restricting PowerShell execution, monitoring unexpected driver-service creation, enforcing vulnerable-driver blocklists, and tracking anomalous outbound connections to blockchain RPC infrastructure.

Severity: Critical

Threat Details and IOCs

Malware: Cruciferra, ErrTraffic, Lumma, Lumma Stealer, Remus, Tenzor
Technologies: Bitdefender, CrowdStrike, Microsoft Defender Antivirus, Microsoft Defender for Endpoints, Microsoft Windows, MocoMsys DCRCVDrv.Sys, Palo Alto Networks Cortex XDR, SentinelOne, Sophos, WordPress
Threat Actors: ClickFix, Cruciferra, LenAI
Attacker IPs: 178[.]16[.]52[.]101
Attacker Domains: 1rpc[.]io, analysis-id-fmd[.]info, analysis-id-lfg[.]info, gateway[.]tenderly[.]co, karmactive[.]com, makeverizyjar[.]info, polygon-bor-rpc[.]publicnode[.]com, polygon[.]drpc[.]org, polygon[.]lava[.]build, polygon-mainnet[.]gateway[.]tatum[.]io, polygon-mainnet[.]public[.]blastapi[.]io, polygon-public[.]nodies[.]app, polygon[.]rpc[.]hypersync[.]xyz, polygon[.]rpc[.]subquery[.]network, polygon[.]therpc[.]io, rpc[.]ankr[.]com, rpc-mainnet[.]matic[.]quiknode[.]pro, tzpx[.]courses, zelpx[.]garden
Attacker Hashes: 0ae0a7f118b80e4655b8b86bb421c151a8f17930e76e714b2fa199409f3af9ce, 47d922b0fd5d704025d14ef98ded46e74830a423, 567c158ee0858f8e941d4ab7a6c18dbc, 87e8d39db624f37d3e77aedf487a2dfd197f71a4730ea74f4e7a4341deaec2ff
Victim Industries: Education, Energy, Financial Services, Government, Healthcare, Hospitality, Legal and Professional Services, Manufacturing, Mining, Retail, Technology Hardware, Telecommunications, Transportation, Travel, Utilities
Victim Countries: India, South Korea, United States

Mitigation Advice

  • Using your Endpoint Detection and Response (EDR) or antivirus solution, create a block rule for any file with the SHA-256 hash 87e8d39db624f37d3e77aedf487a2dfd197f71a4730ea74f4e7a4341deaec2ff, which corresponds to the vulnerable driver DCRCVDrv.sys.
  • Using your Endpoint Detection and Response (EDR) or antivirus solution, create a block rule for any file with the SHA-256 hash 0ae0a7f118b80e4655b8b86bb421c151a8f17930e76e714b2fa199409f3af9ce, which corresponds to the malicious mscoree.dll.
  • Enable the Microsoft vulnerable driver blocklist. This can be done via the 'Block vulnerable signed drivers' Attack Surface Reduction (ASR) rule in Microsoft Defender for Endpoint or by deploying a Windows Defender Application Control (WDAC) policy.
  • In your SIEM or EDR, hunt for PowerShell (powershell.exe) processes that have a parent process of a web browser (e.g., chrome.exe, firefox.exe, msedge.exe) and contain encoded command flags ('-enc', '-encodedcommand') or clipboard-related commands ('Get-Clipboard', 'FromBase64String') in the command line arguments.
  • In your EDR or process monitoring logs, hunt for anomalous executions of 'ServiceModelReg.exe', especially if it is making outbound network connections, has unexpected child processes, or is launched by a non-standard parent process.
  • In your SIEM or EDR, create a detection rule or run a hunt query for the creation of new .sys files in the C:\\Windows\\Temp\\ directory, followed by the creation of a new system service (Event ID 7045 or 4697) pointing to that file.

Compliance Best Practices

  • Develop and deploy a recurring user awareness training module that specifically warns users against copying and pasting commands from any website into PowerShell or a command prompt. Use the fake CAPTCHA lure from the article as a concrete example of this manipulation technique.
  • Implement PowerShell Constrained Language Mode for all non-administrator users via Group Policy or an endpoint management solution. This restricts access to sensitive language elements and cmdlets that can cause damage, while still allowing legitimate scripts to run.
  • Enable PowerShell Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103) across all Windows endpoints via Group Policy. Ensure these logs are forwarded to your SIEM for centralized analysis and alerting on suspicious script content.
  • Begin a phased rollout of an application allowlisting solution, such as Windows Defender Application Control (WDAC), to enforce a policy that only allows approved applications, DLLs, and drivers to execute on endpoints, particularly on critical servers and for privileged users.
  • Create a recurring task for the security team to research and develop high-fidelity detection rules in the EDR and SIEM for generic MITRE ATT&CK techniques mentioned, such as T1574.001 (DLL Side-Loading), T1055.012 (Process Hollowing), and T1218.011 (Rundll32) by looking for behavioral anomalies rather than specific indicators.

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation in the wild. These security flaws include CVE-2026-65400 (CVSS score: 9.8), an improper authentication vulnerability in Apple macOS Screen Sharing that has been abused to deploy Monero cryptocurrency miners, and CVE-2026-55040 (CVSS score: 9.1), a weak authentication bypass in Microsoft SharePoint exploited following the public release of proof-of-concept code. Additionally, CVE-2026-59310 (CVSS score: 9.8), a path traversal vulnerability in Broadcom VMware vCenter, has been leveraged by a suspected China-nexus advanced persistent threat (APT) actor to deploy backdoors, reverse SSH binaries, and Babuk-derived ransomware, compromising 361 unique IP addresses across 47 countries, with the highest concentrations in Germany, the United States, and Turkey. Finally, CVE-2026-33824 (CVSS score: 9.8), a double free vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions, is being actively exploited by a Chinese-speaking threat actor utilizing manual operations alongside an AI-enabled autonomous hacking campaign powered by DeepSeek. Federal Civilian Executive Branch (FCEB) agencies must update all vulnerable systems to the latest patched versions by August 21, 2026, to mitigate these active threats.

Severity: Critical

Threat Details and IOCs

Malware: Babuk, Babuk Locker, Babyk, Vasa Locker
CVEs: CVE-2026-33824, CVE-2026-55040, CVE-2026-59310, CVE-2026-65400
Technologies: Apple macOS, Microsoft SharePoint, Microsoft Windows, Microsoft Windows Server, VMware vCenter Server
Threat Actors: Babuk, ChaoticEclipse, Cl0p Ransomware Group, DeadEclipse, Knaithe, KnYuan, MSNightmare, Nightmare-Eclipse
Attacker Countries: China
Attacker Domains: api[.]deepseek[.]com, code[.]newcli[.]com, dashscope[.]aliyuncs[.]com
Attacker URLs: code[.]newcli[.]com/codex/v1, code[.]newcli[.]com/ultra
Victim Industries: Education, Financial Services, Government, Information Technology, Manufacturing, Retail, Technology Hardware, Telecommunications
Victim Countries: France, Germany, Iran, Turkey, United States

Mitigation Advice

  • Immediately apply the security patches for the Broadcom VMware vCenter path traversal vulnerability (CVE-2026-59310).
  • Immediately apply the security patches for the Microsoft SharePoint weak authentication vulnerability (CVE-2026-55040).
  • Immediately apply the latest Windows security updates to patch the Microsoft Internet Key Exchange (IKE) Service Extensions double free vulnerability (CVE-2026-33824).
  • Immediately apply the latest security updates to all Apple macOS devices to patch the improper authentication vulnerability (CVE-2026-65400).
  • Review and enforce firewall rules to ensure the VMware vCenter management interface is not exposed to the internet and is only accessible from a trusted, isolated management network.
  • On VMware vCenter servers, hunt for indicators of compromise such as the presence of unexpected backdoors or 'reverse_ssh' binaries, and monitor for unusual outbound network connections.
  • Identify all macOS devices with Screen Sharing enabled and disable the service if it is not essential for business operations.

Compliance Best Practices

  • Implement network segmentation to create a dedicated, isolated management VLAN for critical infrastructure like VMware vCenter servers, strictly controlling all inbound and outbound traffic.
  • Deploy and configure a Web Application Firewall (WAF) in front of the Microsoft SharePoint server to inspect and filter incoming web traffic for malicious patterns.
  • Configure VMware vCenter to forward all system, security, and application logs to a centralized SIEM and develop alert rules for suspicious activities like backdoor installation or unexpected SSH connections.
  • Implement a Mobile Device Management (MDM) solution to enforce security policies, manage configurations, and automate patching for all Apple macOS endpoints.
  • Deploy and tune endpoint monitoring tools to detect signs of resource hijacking, such as sustained high CPU utilization or network connections to known cryptocurrency mining pools.
  • Evaluate the current remote access VPN architecture and consider migrating from traditional IKE/IPsec VPNs to a Zero Trust Network Access (ZTNA) solution to reduce the attack surface and enforce user- and device-based access policies.

Critical Elementor Pro File Upload Flaw Enables Unauthenticated Remote Code Execution on WordPress Sites

A critical vulnerability, CVE-2026-32475 (CVSS 9.0), affects the Elementor Pro WordPress plugin (versions up to and including 4.2.1), enabling unauthenticated remote code execution (RCE) via the Forms module's file upload handling. The flaw stems from a logic discrepancy where extension validation and file-move steps execute in separate loops with differing handling of empty file entries, allowing attackers to bypass the extension blocklist by submitting two file parts for a single File Upload field. This writes arbitrary PHP files to the publicly accessible `wp-content/uploads/elementor/forms/<uniqid>.php` directory. To mitigate this threat, administrators must upgrade Elementor Pro to version 4.2.2 or later, audit the upload directory for unauthorized PHP files, and consider implementing Web Application Firewall (WAF) rules to block PHP uploads at form endpoints. Additionally, a related WordPress core vulnerability, CVE-2026-65640 (CVSS 8.8), allows Author-level users or higher to achieve RCE via malicious PostScript uploads on servers running Imagick and Ghostscript; this affects WordPress core versions 4.7 through 7.0 and requires an upgrade to version 7.0.4.

Severity: Critical

Threat Details and IOCs

Malware: StopAndProtect
CVEs: CVE-2026-32475, CVE-2026-65640
Technologies: Artifex Ghostscript, Elementor, ImageMagick, PHP, WordPress

Mitigation Advice

  • Upgrade all instances of the Elementor Pro WordPress plugin to version 4.2.2 or later.
  • Update all WordPress core installations to version 7.0.4 or a patched version specific to your release branch.
  • Scan the 'wp-content/uploads/elementor/forms/' directory on all WordPress servers for any unexpected PHP files and investigate any findings immediately.
  • Implement a Web Application Firewall (WAF) rule to block file uploads containing PHP extensions to all WordPress form submission endpoints.

Compliance Best Practices

  • Establish a formal policy to periodically review all public-facing web forms and disable any file upload fields that are not strictly required for business operations.
  • Configure web server rules to prevent the execution of scripts (e.g., PHP) within the 'wp-content/uploads' directory and all its subdirectories.
  • Deploy and configure a File Integrity Monitoring (FIM) solution to generate real-time alerts on the creation or modification of executable files within WordPress upload directories.
  • Implement and maintain an automated patch management system for all WordPress components, including core, themes, and plugins, to ensure timely application of security updates.
  • Conduct a quarterly audit of all WordPress user accounts, enforcing the principle of least privilege by removing unnecessary 'upload_files' capabilities and limiting the number of users with roles such as Author, Editor, or Administrator.

Authors & Contributors

Brian Sayer (Author)

Threat Intelligence Analyst, F5