CVE-2026-19490 is a critical (CVSS 9.3) authentication bypass (CWE-288) in NetScaler ADC and NetScaler Gateway that allows unauthenticated attackers to forge sessions via the SAML HTTP-Redirect binding handler (/cgi/samlauth). It requires no privileges or user interaction, is actively exploited in the wild, and is listed in CISA KEV, making it a textbook T1190 initial-access vulnerability against internet-facing edge appliances.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-08-19
Added to CISA KEV: 2026-09-09 21 DAYS BETWEEN CVE AND KEV
CVE-2026-19490 is a critical authentication bypass vulnerability affecting NetScaler ADC and NetScaler Gateway appliances [1][4]. The flaw, classified under CWE-288, enables an unauthenticated attacker to perform session forgery via the SAML HTTP-Redirect binding handler [2][4]. This vulnerability is significant because it allows remote adversaries to gain unauthorized access to the target system without requiring elevated privileges or user interaction, posing a severe threat to internet-facing infrastructure [1].
CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. ... On August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. Theβ¦
Unauthenticated session forgery on Citrix NetScaler ADC / NetScaler Gateway via the SAML HTTP-Redirect binding handler at GET /cgi/samlauth .
Attackers are actively exploiting CVE-2026-19490, a critical NetScaler auth bypass. Here's how to detect, contain, and remediate before your edge becomes the entry point.
CVE-2026-19490 is a critical authentication bypass vulnerability in NetScaler ADC and NetScaler Gateway. It is classified as CWE-288 and allows ...
The flaw applies to NetScaler ADC versions from 14.1 through 73.32 and from 13.1 through 63.21, and to NetScaler Gateway versions in the same range. Administrators should check the firmware version of their appliances against these ranges.