Critical NetScaler SAML Bypass CVE-2026-19490 Scores 9.3, Exploits Already Observed
A critical vulnerability tracked as CVE-2026-19490 affects Citrix NetScaler ADC and NetScaler Gateway, allowing attackers to forge SAML assertions and obtain valid sessions without a legitimate signature. Citrix published advisory CTX696939 on August 19, 2026, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 9, 2026, confirming active exploitation in the wild. The vulnerability carries a CVSS v4.0 score of 9.3 and is particularly dangerous because compromised sessions appear legitimate to downstream systems, leaving no obvious trace in authentication logs. Affected builds include NetScaler ADC and Gateway versions 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, with no workaround available — patching to a fixed build is the only complete remedy. End-of-life branches 12.1 and 13.0 will not receive fixes and should be replaced or isolated, while a ZoomEye scan identified over 239,000 publicly reachable NetScaler instances, underscoring the scale of potential exposure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in