Citrix NetScaler ADC and NetScaler Gateway Memory Overflow and Authentication Bypass

Release Date: 4th September 2026

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilise Citrix NetScaler ADC and/or NetScaler Gateway products. This alert is intended for a technical audience.

What is it?

Citrix has disclosed two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, critical edge devices that organisations use to securely deliver applications, data, and remote access to users, and which are frequently targeted by threat actors as an entry point into sensitive environments. CVE-2026-19489 is a memory overflow vulnerability that requires SIP ALG (Session Initiation Protocol Application Layer Gateway) to be enabled on a Large Scale NAT (LSN) group configuration, and can lead to unpredictable device behaviour or denial of service.

Reference

  1. https://support.citrix.com/external/article/CTX696939/netscaler-adc-and-netscaler-gateway-secu.html
  2. https://www.cve.org/CVERecord?id=CVE-2026-19489
  3. https://www.cve.org/CVERecord?id=CVE-2026-19490