ACSC warns of critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway – Australian Cyber Security Magazine

ACSC warns of critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway – Australian Cyber Security Magazine

By Editorial Team
Publication Date: 2026-09-04 05:38:00


The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) has issued a critical alert for Australian organisations using Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products, warning of two vulnerabilities and urging rapid patching.

In an alert dated 4 September 2026, the ACSC said Citrix had identified the issues in NetScaler ADC and NetScaler Gateway, which are commonly deployed as edge devices to deliver applications, data and remote access. The agency noted that edge devices are frequently targeted by threat actors as an entry point into sensitive environments.

The vulnerabilities are tracked as CVE-2026-19489 and CVE-2026-19490. According to the ACSC, CVE-2026-19489 is a memory overflow vulnerability that requires SIP ALG (Session Initiation Protocol Application Layer Gateway) to be enabled on a Large Scale NAT (LSN) group configuration….