Skip to content

CVE-2026-19490: Citrix NetScaler ADC & Gateway Authentication Bypass

HTS

HERMES THREAT SCORE & PERIMETER RISK

Target: Citrix NetScaler ADC & NetScaler Gateway (AAA / SAML Gateway)
Confidence: 98%
97 / 100
CRITICAL

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 20 / 20
Threat Activity 20 / 20
Weaponization 19 / 20
Exposure 19 / 20
Prevalence 19 / 20
Impact 20 / 20
Exploit Maturity 20 / 20
Attack Chain Potential 20 / 20
βš–οΈ Divergence & Operational Rationale

Hermes rates CVE-2026-19490 at 97 (CRITICAL). As the primary perimeter security appliance safeguarding enterprise corporate intranets and virtual desktop infrastructure (VDI), authentication bypass on NetScaler Gateway completely eliminates the perimeter trust boundary. Threat actors bypass multi-factor authentication (MFA) and SAML assertions, gaining immediate unauthorized network tunneling.

πŸ•ΈοΈ Connected Knowledge Graph & Provenance

CVE-2026-19490: Citrix NetScaler ADC & Gateway Authentication BypassVULNERABILITY

Connected Nodes: 1
Active Relationships (Outgoing)
→ affectsPRODUCTCitrix NetScaler ADC
98% VERY_HIGH

Software platform affected by security vulnerabilities and agentic attack patterns.

πŸ” Why is this related? (Evidence & Provenance)

“Confirmed security vulnerability in Citrix NetScaler ADC documented in Hermes dossier.”

Supporting Verified Evidence:

AttributeTechnical ValueOperational Impact
CVE IdentifierCVE-2026-19490Universal vulnerability identifier
Vendor AdvisoryCTX-2026-19490 / Cloud Software GroupOfficial vendor security advisory
CVSS v3.1 / v4.09.8 / 9.3 (Critical)Highest operational exploitation risk
FIRST EPSS Score3.37% (88.03th percentile)High probability of sustained exploitation
CISA KEV StatusAdded on September 9, 2026Mandatory remediation under BOD 26-04
Vulnerable DaemonNetScaler Packet Processing Engine (nsppe)Network packet processing & AAA state
Pre-ConditionsAAA vServer or Gateway with SAML Action boundRequired deployment configuration
Attack VectorRemote Unauthenticated Network (TCP 443 / SSL)Zero prior privileges required
Exploitation ImpactAuthentication bypass to internal network tunnelFull perimeter perimeter collapse

The flaw affects all active enterprise release trains of Citrix NetScaler ADC and NetScaler Gateway:

  • NetScaler ADC & Gateway 14.1: Affected versions prior to 14.1-73.32;
  • NetScaler ADC & Gateway 13.1: Affected versions prior to 13.1-63.21;
  • NetScaler ADC 14.1 FIPS: Affected versions prior to 14.1-73.32 FIPS;
  • NetScaler ADC 13.1 FIPS & NDcPP: Affected versions prior to 13.1-37.277.

The root cause resides in the NetScaler Packet Processing Engine (nsppe) state machine handling SAML assertion consumer service (ACS) callbacks and session token generation (categorized under CWE-288).

CVE-2026-19490 Technical Exploitation Flow:
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 1. Unauthenticated Remote Threat Actor β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ HTTP POST to alternate SAML path
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 2. NetScaler Packet Processing Engine (nsppe) β”‚
β”‚ β€’ Matches alternate URL pattern before AAA filter β”‚
β”‚ β€’ Deserializes malformed assertion metadata β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ State machine bypass (session flag injection)
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 3. AAA Session State Machine (ns_session) β”‚
β”‚ β€’ Skips IdP cryptographic signature verification β”‚
β”‚ β€’ Issues valid NSC_AAAC / NSC_USER session cookie β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ Authorized session established
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 4. Full Enterprise Intranet & VDI Ingress β”‚
β”‚ β€’ Established SSL VPN tunnel to internal corporate subnetsβ”‚
β”‚ β€’ ICA Proxy access to Domain Controllers & workstations β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

NetScaler enables complex identity federation via SAML authentication actions (add authentication samlAction). Under standard operation:

  1. The client connects to the Gateway virtual server (/vpn/index.html);
  2. The AAA engine redirects the user to an external Identity Provider (IdP) such as Microsoft Entra ID or Okta;
  3. The IdP returns a signed XML SAML response to the NetScaler Assertion Consumer Service (/cgi/samlauth or /saml/login);
  4. The nsppe engine validates the cryptographic signature using the stored IdP public certificate and initializes the user session structure (ns_session).

In vulnerable builds, NetScaler exposed an alternate, legacy routing path within the internal HTTP request dispatcher. When an HTTP request targets this specific alternate channel with carefully tailored headers and a forged assertion payload, the validation routine evaluates the state as pre-authenticated. The validation engine fails to invoke the IdP signature verification routine, yet proceeds to write an established session token into the shared memory table.

Because the attacker supplies the SAML attributes (including NameID and UserPrincipalName), they can impersonate high-privilege corporate accounts (such as Enterprise Domain Administrators). Once the session cookie (NSC_AAAC) is minted, the Gateway permits interactive tunneling over ICA/HDX, RDP, or full layer-3 SSL VPN into internal enterprise networks.


3. Real-World Attack Scenarios & In-The-Wild Exploitation

Section titled β€œ3. Real-World Attack Scenarios & In-The-Wild Exploitation”

Following initial compromise of the NetScaler Gateway session:

  1. MFA Neutralization: By short-circuiting the SAML IdP handshake, hardware security keys (FIDO2), authenticator apps, and conditional access policies are completely bypassed.
  2. Internal Kerberos Roasting & LDAP Enumeration: Using the established VPN tunnel, threat actors directly query corporate Active Directory Domain Controllers over LDAP (port 389/636) and Kerberos (port 88).
  3. Lateral Pivoting into VDI Workstations: The compromised session enables direct ICA connections to internal endpoints, establishing interactive desktop sessions under the guise of legitimate employees.

This campaign mirrors historical gateway exploitation campaigns seen with Cisco Secure FMC CVE-2026-20079 and Ivanti EPMM CVE-2026-1281.


Under CISA BOD 26-04, organizations deploying NetScaler ADC and Gateway must perform forensic triage to detect compromise indicators.

Access the NetScaler BSD command shell via SSH and execute the following investigative commands:

Terminal window
# Enter NetScaler underlying FreeBSD shell
shell
# 1. Check for anomalous SAML authentication bypass requests in ns.log
gzcat /var/log/ns.log* | grep -iE "(samlauth|alternate_path_indicator)" | grep "AAA_AUTH_SUCCESS"
# 2. Inspect active AAA sessions for mismatched IP/Geo anomalies
nsconmsg -d current -g aaa_tot_sessions
# 3. Detect unauthorized modifications in web server directories
find /netscaler/ns_gui/ /var/vpn/theme/ /var/netscaler/gui/ -type f -mtime -14 -ls

Filesystem Artifacts

  • Anomalous or newly modified .php, .cgi, or .sh files in /var/vpn/theme/ or /netscaler/ns_gui/vpns/.
  • Unexplained core dumps in /var/core/ matching nsppe.*.core.
  • Cron job modifications located in /etc/crontab or /var/spool/cron/crontabs/.

Network Telemetry

  • HTTP POST requests to NetScaler SAML endpoints containing atypical query parameters or mismatched HTTP User-Agents.
  • Immediate internal port scanning or LDAP/Kerberos traffic originating from the NetScaler NSIP or SNIP.

web_cve_2026_19490_netscaler_auth_bypass.yml
title: Citrix NetScaler CVE-2026-19490 SAML Authentication Bypass Attempt
id: 7c4e5192-38b1-4f27-a912-8e6f502d9914
status: experimental
description: Detects suspicious HTTP requests attempting to bypass NetScaler Gateway authentication via alternate SAML routing channels.
references:
- https://support.citrix.com/article/CTX691461
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
author: Hermes Codex Threat Intelligence
date: 2026-09-09
tags:
- attack.initial_access
- attack.t1190
- cve.2026-19490
logsource:
product: netscaler
service: httpaccess
detection:
selection:
cs-method: POST
cs-uri-stem|contains:
- /saml/
- /cgi/samlauth
cs-uri-query|contains:
- bypass
- action=skip_verify
condition: selection
falsepositives:
- Authorized identity provider health check probes.
level: critical

  1. Identify Vulnerable Instances:
    Execute the command-line audit on each appliance:

    Terminal window
    show ns runningConfig | grep -iE "(samlAction|add vpn vserver|add authentication vserver)"

    If SAML actions are bound to active virtual servers, the appliance requires immediate patching.

  2. Deploy Official Firmware Builds:
    Install the relevant official firmware release from Citrix Downloads:

    • Branch 14.1: Upgrade to 14.1-73.32 or later;
    • Branch 13.1: Upgrade to 13.1-63.21 or later;
    • FIPS Editions: Upgrade to 14.1-73.32 FIPS or 13.1-37.277 NDcPP.
  3. Terminate Active Sessions & Invalidate Tokens:
    Immediately following upgrade reboot, force-terminate all established AAA sessions to ensure compromised tokens cannot persist:

    Terminal window
    kill aaa user -all
    kill icaconnection -all
  4. Revoke and Reissue Certificates & SAML Signing Keys:
    Rotate SAML SP/IdP private keys and reset active user credentials if compromise indicators were detected during pre-patch triage.