PT-2026-78351 · Citrix · Netscaler Gateway+1
CVE-2026-19490
·
Published
2026-08-19
·
Updated
2026-09-12
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NetScaler ADC versions 13.1 through 63.21
NetScaler ADC versions 14.1 through 73.32
NetScaler Gateway versions 13.1 through 63.21
NetScaler Gateway versions 14.1 through 73.32
Citrix ADC versions prior to 13.1-54.29
Citrix Gateway versions prior to 13.1-54.29
Citrix ADC versions prior to 14.1-25.53
Citrix Gateway versions prior to 14.1-25.53
NetScaler versions prior to 15.1-4.53
Description
An authentication bypass flaw exists in NetScaler ADC and Gateway appliances when configured as AAA virtual servers or Gateways for services such as SSL VPN, ICA Proxy, CVPN, or RDP Proxy. The issue occurs during the processing of SAML HTTP-Redirect binding at the
/cgi/samlauth endpoint, allowing an unauthenticated attacker to send an unsigned SAMLResponse and obtain a valid session. This can grant full administrative access to the management interface, typically on port 443/tcp, by bypassing SAML or OAuth authentication. Real-world exploitation attempts have been detected from source IPs in Australia, the United States, and Germany. Approximately 22,000 exposed ADC appliances and 1,700 Gateway instances have been tracked online.Recommendations
Update NetScaler ADC and Gateway versions 13.1 to 13.1-54.29 or later.
Update NetScaler ADC and Gateway versions 14.1 to 14.1-25.53 or later.
Update NetScaler version 15.1 to 15.1-4.53 or later.
Restrict management interface access to trusted IP addresses only using firewall rules or Access Control Lists (ACLs).
Audit logs for unauthorized administrative sessions.
Exploit
Fix
LPE
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netscaler Adc
Netscaler Gateway