Research NetScaler ADC auth-bypass NetScaler Gateway Citrix network-edge
Mind the Config: Detecting and Weaponizing NetScaler CVE-2026-19490
TL;DR
CVE-2026-19490">CVE-2026-19490 is an authentication bypass in the SAML handling on Citrix NetScaler ADC and Gateway, rated CVSS 9.3. A single unauthenticated request makes the appliance run its post-login code, but what that is worth depends entirely on configuration: from a reliable pre-authentication crash, through a proxy into the internal network, up to root on the appliance. Patch to 13.1-63.21 or 14.1-73.32 or later (12.1 and 13.0 are end of life). Patch state is measurable from outside in one safe request, which we published as a CVE-2026-19490-check">detection tool. Read on for a branch-by-branch map from that safe check up to root command execution.…