CVE Tools

Mind the Config: Detecting and Weaponizing NetScaler CVE-2026-19490

Bishop FoxBy Jon Williams, Threat Enablement & Analysis Team15 min read

ResearchNetScaler ADCNetScaler Gateway

Our summary

Bishop Fox researchers released a detailed analysis of CVE-2026-19490, a critical CVSS 9.3 authentication bypass affecting Citrix NetScaler ADC and NetScaler Gateway. The flaw in the SAML handling allows an unauthenticated attacker to trigger various outcomes, ranging from a guaranteed denial-of-service crash to unauthorized access to internal network resources via SSRF, depending heavily on specific appliance configurations. While the vulnerability can lead to root command execution if weak management credentials are present, it primarily serves as a significant pre-authentication entry point for further attacks.

Administrators should upgrade to fixed versions 13.1-63.21 or 14.1-73.32 immediately, noting that versions 12.1 and 13.0 are end-of-life and lack patches. Bishop Fox has also made a safe detection tool available on GitHub to verify patch status remotely with a single non-destructive request.

Read at Bishop Fox

Below is the opening; the full story is at Bishop Fox.

From Bishop Fox

TL;DR

CVE-2026-19490">CVE-2026-19490 is an authentication bypass in the SAML handling on Citrix NetScaler ADC and Gateway, rated CVSS 9.3. A single unauthenticated request makes the appliance run its post-login code, but what that is worth depends entirely on configuration: from a reliable pre-authentication crash, through a proxy into the internal network, up to root on the appliance. Patch to 13.1-63.21 or 14.1-73.32 or later (12.1 and 13.0 are end of life). Patch state is measurable from outside in one safe request, which we published as a CVE-2026-19490-check">detection tool. Read on for a branch-by-branch map from that safe check up to root command execution.…

Continue at Bishop Fox

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store