CVE-2026-19490 is a critical authentication bypass vulnerability affecting Citrix NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway).
When the NetScaler appliance is deployed as an Authentication, Authorization, and Auditing (AAA) virtual server or as an Enterprise Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) with bound SAML actions, an alternate path in the request processing pipeline fails to enforce authentication validation. An unauthenticated remote threat actor with network access to the Gateway endpoint can craft specific requests that circumvent the SAML validation stage, mint an authenticated administrative or user session, and gain unrestricted entry into internal enterprise networks and virtualized desktop infrastructure without credentials or MFA tokens.