πŸ”΄ CVE-2026-19490

CVE-2026-19490 is a critical (CVSS 9.3) authentication bypass (CWE-288) in NetScaler ADC and NetScaler Gateway that allows unauthenticated attackers to forge sessions via the SAML HTTP-Redirect binding handler (/cgi/samlauth). It requires no privileges or user interaction, is actively exploited in the wild, and is listed in CISA KEV, making it a textbook T1190 initial-access vulnerability against internet-facing edge appliances.

← Back to Overview
HIGH_RISK
Risk Level
9.3
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 β€” Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

πŸ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-08-19

Added to CISA KEV: 2026-09-09 21 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

πŸ” Web Intelligence (Kagi Β· 2026-09-14)

Summary

CVE-2026-19490 is a critical authentication bypass vulnerability affecting NetScaler ADC and NetScaler Gateway appliances [1][4]. The flaw, classified under CWE-288, enables an unauthenticated attacker to perform session forgery via the SAML HTTP-Redirect binding handler [2][4]. This vulnerability is significant because it allows remote adversaries to gain unauthorized access to the target system without requiring elevated privileges or user interaction, posing a severe threat to internet-facing infrastructure [1].

Exploitation

  • Active Exploitation: There are reports of active exploitation of this vulnerability in the wild by threat actors targeting edge appliances [3].
  • PoC Availability: Public proof-of-concept (PoC) code exists, specifically demonstrating unauthenticated session forgery via the `/cgi/samlauth` endpoint [2].
  • Attack Prerequisites: Exploitation occurs remotely over the network and does not require authentication or user interaction [1].

Affected Products & Patches

  • Affected Versions:
- NetScaler ADC: Versions 14.1 through 73.32 and 13.1 through 63.21 [5]. - NetScaler Gateway: Versions within the same release ranges as the ADC [5].
  • Remediation: The primary fix is to upgrade the vulnerable NetScaler instances to a release and build version that contains the security patch [6].

Impact

  • System Access: Successful exploitation provides an attacker with the ability to bypass authentication mechanisms and potentially perform unauthorized administrative or user-level actions by forging sessions [2][4].
  • Business Risk: Internet-facing deployments are at extreme risk, as the appliance serves as an entry point into the network; compromise may lead to full system takeover, lateral movement, and unauthorized access to internal resources protected by the gateway [1][3].

Sources

  1. CVE-2026-19490: Critical Vulnerability Affecting Citrix ...

    CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. ... On August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The…

  2. CVE-2026-19490 β€” NetScaler ADC/Gateway SAML ...

    Unauthenticated session forgery on Citrix NetScaler ADC / NetScaler Gateway via the SAML HTTP-Redirect binding handler at GET /cgi/samlauth .

  3. CVE-2026-19490: Critical Citrix NetScaler Auth Bypass Actively ...

    Attackers are actively exploiting CVE-2026-19490, a critical NetScaler auth bypass. Here's how to detect, contain, and remediate before your edge becomes the entry point.

  4. CVE-2026-19490: Critical Citrix NetScaler Flaw

    CVE-2026-19490 is a critical authentication bypass vulnerability in NetScaler ADC and NetScaler Gateway. It is classified as CWE-288 and allows ...

  5. CVE-2026-19490 - Vulnerability Details - OpenCVE

    The flaw applies to NetScaler ADC versions from 14.1 through 73.32 and from 13.1 through 63.21, and to NetScaler Gateway versions in the same range. Administrators should check the firmware version of their appliances against these ranges.