ASD's ACSC warns of actively exploited Citrix NetScaler vulnerabilities

By Staff Writer on Sep 28, 2026 11:28AM
ASD's ACSC warns of actively exploited Citrix NetScaler vulnerabilities

In summary

  • Australia's cyber security authority is urging organisations to immediately patch eight newly disclosed vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • At least two flaws, CVE-2026-88771 and CVE-2026-8872, were exploited globally before patches became available, though no confirmed exploitation has been reported in Australia.
  • The ACSC advised reviewing device logs for suspicious activity and assessing pre-condition requirements for each CVE to determine prior exposure.

Australia's cyber security authority has urged organisations running Citrix NetScaler ADC and Citrix NetScaler Gateway to apply patches immediately after Citrix disclosed eight new vulnerabilities, at least two of which were under active exploitation before fixes became available.

The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) said it had not yet received reports of confirmed exploitation in Australia but warned that two of the flaws — CVE-2026-88771 and CVE-2026-8872 — had been exploited globally prior to a patch being released.

CVE-2026-88771 is a remote code execution vulnerability that allows an unauthenticated attacker to execute arbitrary commands. The ACSC said all configurations of Citrix NetScaler ADC and Citrix NetScaler Gateway are affected and vulnerable to exploitation against this flaw.

The remaining seven vulnerabilities require specific device configurations to be in place before they can be exploited. Citrix has published instructions for customers to determine whether their devices are exposed to each of those CVEs.

The ACSC recommended that organisations review the vulnerability details published by Citrix and install the available security update as a priority. It also advised organisations to assess the pre-condition requirements for each CVE to understand where they may have been exposed prior to patching.

In addition to patching, the ACSC said organisations should review device logs for suspicious activity consistent with the types of attacks each vulnerability enables, particularly where pre-conditions for exploitation were met.

Earlier this month, Citrix released patches for a pair of critical vulnerabilities affecting its NetScaler ADC and NetScaler Gateway products.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © nextmedia Pty Ltd. All rights reserved.

Add techpartner.news as your trusted source

Tags:

Log in

Email:
Password:
  |  Forgot your password?