ACSC warns of actively exploited vulnerabilities in Citrix NetScaler products

The Australian Cyber Security Centre (ACSC) has issued a critical alert for Australian organisations running Citrix NetScaler ADC and Citrix NetScaler Gateway, warning of multiple newly disclosed vulnerabilities and urging

ACSC warns of actively exploited vulnerabilities in Citrix NetScaler products

ACSC warns of actively exploited vulnerabilities in Citrix NetScaler products


The Australian Cyber Security Centre (ACSC) has issued a critical alert for Australian organisations running Citrix NetScaler ADC and Citrix NetScaler Gateway, warning of multiple newly disclosed vulnerabilities and urging customers to apply vendor updates.

In an alert dated 28 September 2026, the ACSC said Citrix had released details of eight vulnerabilities affecting the products. The ACSC said it understood at least two of the flaws had been under active exploitation globally before a patch was available, though it had not received reports of confirmed exploitation in Australia.

One of the vulnerabilities, CVE-2026-88771, was described as a remote code execution issue that could allow an unauthenticated attacker to execute arbitrary commands. The ACSC said all configurations of Citrix NetScaler ADC and Citrix NetScaler Gateway were affected by that vulnerability.

The ACSC said the remaining seven vulnerabilities required specific configurations for exploitation to be possible, and that Citrix had provided instructions for customers to determine whether devices were vulnerable to each CVE.

As mitigation, the ACSC recommended organisations review Citrix’s security bulletin and install the security update. It also advised organisations to consider internal security assessments and business plans when prioritising implementation, review the pre-conditions for each CVE to understand potential exposure, and check device logs for suspicious activity consistent with the attacks enabled by the vulnerabilities.

The ACSC said organisations that had been impacted, suspected impact, or required advice could contact the Australian Cyber Security Hotline via 1300 CYBER1 (1300 292 371). The alert was also published on cyber.gov.au.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.