Citrix has released patches for a pair of critical vulnerabilities affecting its NetScaler ADC and NetScaler Gateway products, with Australia's cyber security authority urging organisations to apply the fixes as a priority.
Both products are critical edge devices used in enterprise networking to deliver applications, data and remote access to users.
Critical edge devices are frequently targeted by threat actors as entry points into sensitive environments, the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) stated.
The first vulnerability, CVE-2026-19489, is a memory overflow flaw. It is triggered when SIP ALG (Session Initiation Protocol Application Layer Gateway) is enabled on a Large Scale NAT group configuration.
The second, CVE-2026-19490, is an authentication bypass vulnerability. It is present where SAML actions are enabled or where the device is configured as a VPN gateway.
The ASD's ACSC said it has no information indicating a specific industry or sector is being targeted, but advised all organisations running affected Citrix products to act promptly.
The ASD's ACSC is advising organisations to review Citrix's mitigation guidance, assess their networks for vulnerable product versions, and update to the latest patched releases as soon as practicable.
For organisations whose NetScaler ADC or NetScaler Gateway deployments are managed by a third party - including MSPs and enterprise IT providers - the ASD's ACSC specifically advised contacting that provider to confirm the products have been patched and are being monitored for suspicious activity.




