Citrix NetScaler SAML Bypass CVE-2026-19490 Exposes Hundreds of Thousands of Gateways
A critical SAML authentication bypass vulnerability, CVE-2026-19490, has been identified in Citrix NetScaler ADC and Gateway, carrying a CVSS score of 9.8. The flaw allows attackers to forge sessions by presenting fraudulent SAML assertions that the gateway accepts as valid, potentially granting unauthorized access to all applications behind it. An emergency patch was released in August 2026, but active exploitation was still being reported in subsequent weeks. Internet scans conducted via ZoomEye on September 22, 2026, found between approximately 117,000 and 239,000 publicly reachable NetScaler assets, depending on the query fingerprint used. Security teams are advised to verify patch levels on every NetScaler instance handling SAML authentication and to audit logs for anomalous or forged authentication assertions.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in