First published: 04 Sep 2026
Last updated: 04 Sep 2026

Content written for

Small & medium business
Large organisations & infrastructure
Government

This alert is relevant to all Australian organisations that utilise Citrix NetScaler ADC and Citrix NetScaler Gateway products. It is intended for a technical audience.

Background

Citrix has identified two vulnerabilities affecting their NetScaler ADC and NetScaler Gateway products.

Citrix NetScaler ADC and NetScaler Gateway are critical edge devices in enterprise networking that help organisations securely deliver applications, data, and remote access to users.

CVE-2026-19489 is a memory overflow vulnerability. This vulnerability requires SIP ALG (Session Initiation Protocol Application Layer Gateway) to be enabled on a Large Scale NAT (LSN) group configuration.

CVE-2026-19490 is an authentication bypass vulnerability. This vulnerability requires SAML actions to be enabled and/or being configured as a VPN gateway.

Patches were released on 19 August 2026. Organisations should apply patches as a priority.

Critical edge devices are frequently targeted by threat actors as an entry point into sensitive environments.

The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has no information to indicate that a specific industry or sector is being targeted.

Mitigation advice

ASD's ACSC advises organisations to ensure the following:

  • Review the mitigation advice on the vendor support page.
  • Assess networks and environments for the presence of vulnerable versions of Citrix products.
  • Update affected products to the latest versions and apply patches as soon as practicable.
  • If your Citrix NetScaler ADC and NetScaler Gateway products are managed by a third party, such as a MSP or Enterprise IT provider, you should contact that provider to ensure the products have been patched and are being monitored for suspicious activity.
  • If suspicious activity is detected, notify ASD’s ACSC.

Where to get help

Organisations that have been impacted, suspect impact or require advice and assistance can contact us via 1300 CYBER1 (1300 292 371).

Was this helpful?
Yes this was helpful
No this was not helpful

Thanks for your feedback!

We welcome additional feedback below.

Was this information easy to understand?
Will you take action after reading this?
Did you find the information you were looking for?
Did the design and layout of this page meet your expectations?