ZoomEye: Over 239,000 Citrix NetScaler Gateways Exposed Amid SAML Bypass
ZoomEye measured the internet footprint of Citrix NetScaler ADC and Gateway: 239,130 assets matched the full product fingerprint and 116,773 the shorter one. The scan follows CVE-2026-19490, a CVSS 9.8 SAML authentication bypass enabling session forgery that was fixed in an emergency patch in August 2026.
- CVE-2026-19490 is rated CVSS 9.8 and enables session forgery via SAML bypass
- An emergency patch shipped in August 2026, but exploitation continues
- ZoomEye counted 239,130 assets matching app="Citrix NetScaler"
- The shorter app="NetScaler" fingerprint returned 116,773 assets
Read next
Security