CVE-2026-19490: NetScaler SAML Bypass Detection and Mitigation
An authentication bypass via SAML (CWE-288, CVSS 9.3) has been found in NetScaler ADC and Gateway: the device accepts an assertion without a valid signature and grants a session as any user. Citrix issued bulletin CTX696939, and CISA added the vulnerability to its exploited catalog on September 9, 2026.
- Vulnerable builds: 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, including FIPS and NDcPP
- Fix is update only: vendor offered no workarounds
- ZoomEye found 239,130 Citrix NetScaler instances online
- Unsupported 12.1 and 13.0 branches will not receive a patch
Read next
Security