Mind the Config: Detecting and Weaponizing NetScaler CVE-2026-19490
ResearchNetScaler ADCNetScaler GatewayOur summary
Bishop Fox researchers released a detailed analysis of CVE-2026-19490, a critical CVSS 9.3 authentication bypass affecting Citrix NetScaler ADC and NetScaler Gateway. The flaw in the SAML handling allows an unauthenticated attacker to trigger various outcomes, ranging from a guaranteed denial-of-service crash to unauthorized access to internal network resources via SSRF, depending heavily on specific appliance configurations. While the vulnerability can lead to root command execution if weak management credentials are present, it primarily serves as a significant pre-authentication entry point for further attacks.
Administrators should upgrade to fixed versions 13.1-63.21 or 14.1-73.32 immediately, noting that versions 12.1 and 13.0 are end-of-life and lack patches. Bishop Fox has also made a safe detection tool available on GitHub to verify patch status remotely with a single non-destructive request.
Below is the opening; the full story is at Bishop Fox.
From Bishop Fox
TL;DR
CVE-2026-19490">CVE-2026-19490 is an authentication bypass in the SAML handling on Citrix NetScaler ADC and Gateway, rated CVSS 9.3. A single unauthenticated request makes the appliance run its post-login code, but what that is worth depends entirely on configuration: from a reliable pre-authentication crash, through a proxy into the internal network, up to root on the appliance. Patch to 13.1-63.21 or 14.1-73.32 or later (12.1 and 13.0 are end of life). Patch state is measurable from outside in one safe request, which we published as a CVE-2026-19490-check">detection tool. Read on for a branch-by-branch map from that safe check up to root command execution.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.