Critical Citrix NetScaler Flaw CVE-2026-19490 Allows Authentication Bypass via SAML
A critical vulnerability, CVE-2026-19490, has been identified in Citrix NetScaler ADC and NetScaler Gateway, carrying a CVSS v4.0 score of 9.3. The flaw stems from a logic error in the SAML HTTP-Redirect binding handler that fails to enforce signature verification, allowing attackers to submit unsigned assertions and obtain valid sessions without any credentials or cryptographic material. Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, along with corresponding FIPS and NDcPP builds, while end-of-life branches 12.1 and 13.0 will not receive patches. Citrix published advisory CTX696939 on August 19, 2026, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 9, 2026. Because NetScaler operates as boundary infrastructure, a successful exploit could expose all resources behind the gateway, and the attack leaves no signature-failure log entries, making detection particularly difficult.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in