ACSC warns of critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
ACSC warns of critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) has issued a critical alert for Australian organisations using Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products, warning of two vulnerabilities and urging rapid patching.
In an alert dated 4 September 2026, the ACSC said Citrix had identified the issues in NetScaler ADC and NetScaler Gateway, which are commonly deployed as edge devices to deliver applications, data and remote access. The agency noted that edge devices are frequently targeted by threat actors as an entry point into sensitive environments.
The vulnerabilities are tracked as CVE-2026-19489 and CVE-2026-19490. According to the ACSC, CVE-2026-19489 is a memory overflow vulnerability that requires SIP ALG (Session Initiation Protocol Application Layer Gateway) to be enabled on a Large Scale NAT (LSN) group configuration. CVE-2026-19490 is an authentication bypass vulnerability that requires SAML actions to be enabled and/or the product to be configured as a VPN gateway.
The ACSC said patches were released on 19 August 2026 and advised organisations to apply them as a priority. It also recommended organisations review the vendor’s mitigation guidance, identify whether vulnerable versions are present in their environments, and update affected products to the latest versions as soon as practicable.
For organisations that use managed service providers or third parties to operate Citrix NetScaler, the ACSC advised confirming that patching has been completed and that systems are being monitored for suspicious activity. If suspicious activity is detected, the ACSC said organisations should notify the agency.
The agency said it had no information indicating that a specific industry or sector is being targeted.
Organisations impacted, suspecting impact, or requiring assistance can contact the ACSC via 1300 CYBER1 (1300 292 371). The alert links to Citrix’s vendor advisory and a full version of the ACSC notice on cyber.gov.au.