Security News

ACSC Confirms Active Exploitation of Citrix NetScaler Flaws in Australia

Key Takeaway If your business uses Citrix NetScaler ADC or Gateway, patch immediately and check logs for signs of compromise going back to early September.

The Australian Cyber Security Centre (ACSC) has updated its critical alert on vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway, confirming it has now received reports of exploitation from Australian organisations. Businesses using these products should check for signs of compromise dating back to at least 4 September 2026.

Citrix has disclosed eight vulnerabilities, tracked as CVE-2026-88771 through CVE-2026-88778, with guidance published in a security bulletin. At least two of these, CVE-2026-88771 and CVE-2026-88772, were being actively exploited worldwide before a patch was available. CVE-2026-88771 is particularly serious: it allows an unauthenticated attacker to remotely execute commands, and it affects all configurations of the two products. The remaining vulnerabilities only affect systems with certain configurations, and Citrix has provided guidance to help customers check their exposure.

The ACSC is urging all organisations running these Citrix products to review the vendor's advisory, apply the available security updates, and check device logs for suspicious activity linked to these vulnerabilities. Businesses should also assess their exposure based on configuration and prioritise patching according to their risk and operational needs. Organisations needing help can contact the ACSC on 1300 CYBER1 (1300 292 371).

Summarised by CISO AI from Australian Cyber Security Magazine. We link back to every original so you can read it yourself.