CyberzSOC

Publication detail
← Back to advisories & guidance

CRITICAL ALERT: Critical vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products ↗ source

September 4, 2026 ASD/ACSC Alert

Summary

Citrix has identified two vulnerabilities affecting their NetScaler ADC and NetScaler Gateway products. Citrix NetScaler ADC and NetScaler Gateway are critical edge devices in enterprise networking that help organisations securely deliver applications, data, and remote access to users. This vulnerability requires SIP ALG (Session Initiation Protocol Application Layer Gateway) to be enabled on a Large Scale NAT (LSN) group configuration. This vulnerability requires SAML actions to be enabled and/or being configured as a VPN gateway. Critical edge devices are frequently targeted by threat actors as an entry point into sensitive environments.

News Coverage

DateSourceArticle
2026-09-04 BleepingComputer Critical Citrix NetScaler auth bypass now leveraged in attacks CVE-2026-19490
2026-08-24 Check Point Research 24th August – Threat Intelligence Report CVE-2026-19489

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-19490 9.3 Critical Citrix NetScaler Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler …
CVE-2026-19489 8.8 High NetScaler ADC Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.