PT-2026-78351 · Citrix · Netscaler Gateway+1

CVE-2026-19490

·

Published

2026-08-19

·

Updated

2026-09-12

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NetScaler ADC versions 13.1 through 63.21 NetScaler ADC versions 14.1 through 73.32 NetScaler Gateway versions 13.1 through 63.21 NetScaler Gateway versions 14.1 through 73.32 Citrix ADC versions prior to 13.1-54.29 Citrix Gateway versions prior to 13.1-54.29 Citrix ADC versions prior to 14.1-25.53 Citrix Gateway versions prior to 14.1-25.53 NetScaler versions prior to 15.1-4.53
Description An authentication bypass flaw exists in NetScaler ADC and Gateway appliances when configured as AAA virtual servers or Gateways for services such as SSL VPN, ICA Proxy, CVPN, or RDP Proxy. The issue occurs during the processing of SAML HTTP-Redirect binding at the /cgi/samlauth endpoint, allowing an unauthenticated attacker to send an unsigned SAMLResponse and obtain a valid session. This can grant full administrative access to the management interface, typically on port 443/tcp, by bypassing SAML or OAuth authentication. Real-world exploitation attempts have been detected from source IPs in Australia, the United States, and Germany. Approximately 22,000 exposed ADC appliances and 1,700 Gateway instances have been tracked online.
Recommendations Update NetScaler ADC and Gateway versions 13.1 to 13.1-54.29 or later. Update NetScaler ADC and Gateway versions 14.1 to 14.1-25.53 or later. Update NetScaler version 15.1 to 15.1-4.53 or later. Restrict management interface access to trusted IP addresses only using firewall rules or Access Control Lists (ACLs). Audit logs for unauthorized administrative sessions.

Exploit

Fix

LPE

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14208
CVE-2026-19490

Affected Products

Netscaler Adc
Netscaler Gateway