Australian organisations using Citrix NetScaler ADC and Citrix NetScaler Gateway products should be aware of critical vulnerabilities identified by Citrix. These vulnerabilities, CVE-2026-19489 and CVE-2026-19490, pose significant risks to enterprise networking environments that rely on these devices for secure application delivery and remote access.
Vulnerability Overview
CVE-2026-19489 is classified as a memory overflow vulnerability. It specifically affects configurations where SIP ALG (Session Initiation Protocol Application Layer Gateway) is enabled on a Large Scale NAT (LSN) group. This configuration can potentially allow attackers to exploit the vulnerability if left unaddressed.
On the other hand, CVE-2026-19490 is an authentication bypass vulnerability that requires SAML actions to be enabled or configured as a VPN gateway. This flaw could allow unauthorized access to sensitive systems if exploited.
Citrix has released patches for these vulnerabilities on 19 August 2026, and organisations are urged to apply these updates as a priority to mitigate potential risks.
Mitigation Recommendations
The Australian Cyber Security Centre (ACSC) advises organisations to take the following actions:
- Review the detailed mitigation advice available on the vendor support page.
- Conduct an assessment of networks and environments to identify any vulnerable versions of Citrix products.
- Update affected products to the latest versions and apply the necessary patches as soon as possible.
- If your Citrix NetScaler ADC and NetScaler Gateway products are managed by a third-party provider, such as a Managed Service Provider (MSP) or Enterprise IT provider, contact them to ensure that the products have been patched and are being monitored for any suspicious activity.
- In the event of detecting suspicious activity, organisations should promptly notify the ACSC.
Given that critical edge devices like Citrix NetScaler products are often targeted by threat actors, it is essential for organisations to remain vigilant and proactive in their cybersecurity measures.
Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.



