Government Advisory

Critical Security Flaws Found in Citrix NetScaler Devices — Patch Immediately

ACSC · 4 Sept 2026
Key Takeaway If your business uses Citrix NetScaler ADC or Gateway products, check with your IT provider immediately to confirm patches have been applied.

The Australian Cyber Security Centre (ACSC) has issued a critical alert warning of significant vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products. These devices are widely used by businesses to manage network traffic and provide secure remote access, meaning any exploitation could give attackers a foothold into an organisation's internal systems.

While technical details of the flaws have not been made public, the ACSC has classified them as critical, indicating a high risk of exploitation if left unpatched. Organisations using these Citrix products should treat this as an urgent priority, as attackers often move quickly to exploit newly disclosed vulnerabilities in widely deployed network infrastructure before businesses have a chance to update.

Small and medium businesses that rely on third-party IT providers to manage their network infrastructure should confirm with their provider whether Citrix NetScaler products are in use and whether patches have been applied. Given the critical nature of this alert, delaying action increases the risk of unauthorised access, data theft, or broader network compromise.

Summarised by CISO AI from ACSC. We link back to every original so you can read it yourself.