Two Citrix NetScaler vulnerabilities affecting Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products have prompted a patching warning for Australian organisations. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has advised organisations using the products to assess their environments and apply available security updates as a priority.
Citrix has identified two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, which are critical edge devices used in enterprise networking to securely deliver applications, data and remote access to users.
Citrix NetScaler Vulnerabilities Affect ADC and Gateway
The first flaw, CVE-2026-19489, is a memory overflow vulnerability. According to the alert, exploitation of this vulnerability requires SIP ALG, or Session Initiation Protocol Application Layer Gateway, to be enabled on a Large Scale NAT (LSN) group configuration.
The second flaw, CVE-2026-19490, is an authentication bypass vulnerability. The vulnerability requires SAML actions to be enabled and/or the affected product to be configured as a VPN gateway.
The conditions required for each vulnerability mean that organisations need to assess their specific Citrix configurations to determine whether affected systems are present in their environments.
Patches Released for Citrix NetScaler products
Citrix released patches for the affected products on August 19, 2026. ASD’s ACSC is urging organisations to review the vendor’s mitigation guidance, identify vulnerable versions of Citrix products and update affected systems to the latest versions.
The advisory places particular emphasis on timely patching because critical edge devices are frequently targeted by threat actors as an entry point into sensitive environments.
However, ASD’s ACSC said it has no information indicating that a specific Australian industry or sector is currently being targeted in connection with these vulnerabilities.
Organisations Urged to Assess Vulnerable Versions
The mitigation guidance calls on organisations to assess their networks and environments for vulnerable versions of Citrix products and apply patches as soon as practicable.
Organisations should also review the mitigation advice provided by Citrix and confirm that affected systems have been updated.
Where NetScaler ADC and NetScaler Gateway products are managed by a third party, organisations are advised to contact the relevant managed service provider (MSP) or enterprise IT provider. They should confirm that the products have been patched and are being monitored for suspicious activity.
This step is particularly relevant for organisations that do not directly manage their Citrix infrastructure and may rely on external providers for patching and monitoring.
Monitoring Remains Important After Patching
Alongside addressing the Citrix NetScaler vulnerabilities, organisations are advised to monitor affected environments for suspicious activity. The alert recommends notifying ASD’s ACSC if suspicious activity is detected.
The two vulnerabilities affect different configurations, with CVE-2026-19489 requiring SIP ALG to be enabled on an LSN group configuration, while CVE-2026-19490 requires SAML actions to be enabled and/or the product to be configured as a VPN gateway.
For Australian organisations using Citrix NetScaler products, the immediate steps outlined by ASD’s ACSC are to identify vulnerable versions, apply the available patches, confirm third-party-managed systems have been addressed and maintain monitoring for suspicious activity.





































