ACSC raises critical alert for vulnerabilities in two Citrix products


Monday, 28 September, 2026

ACSC raises critical alert for vulnerabilities in two Citrix products

ASD’s Australian Cyber Security Centre (ACSC) has released a critical alert over eight new vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway products.

The agency understands that at least two of these vulnerabilities (CVE-2026-88771 and CVE-2026-8872) have been under active exploitation globally prior to a patch becoming available. The ACSC has not yet received reports of confirmed exploitation in Australia.

CVE-2026-88771 is a remote code execution vulnerability, which can allow an unauthenticated attacker to execute arbitrary commands. All configurations of Citrix NetScaler ADC and Citrix NetScaler Gateway are affected and are vulnerable to exploitation against this CVE.

The remaining seven vulnerabilities require certain configurations to be in place for the device to be vulnerable to exploitation. Citrix has provided instructions for customers to check to see if their device is vulnerable to each of the other 7 CVE’s.

Mitigation advice

The ACSC recommends that organisations operating vulnerable Citrix products review details of the vulnerabilities released by the vendor and install the security update. Organisations should consider internal security assessments and business plans, in determining how to effectively prioritise the implementation of this security update.

In addition to applying the security update, organisations should review the pre-condition requirements for each of the CVEs to understand where they may have been vulnerable to exploitation.

ASD’s ACSC recommends reviewing device logging for any suspicious activity, which is consistent with the kinds of attacks enabled by each of the CVE’s where the pre-conditions for exploitation have been met.

Where to get help

Organisations that have been impacted, suspect impact or require advice and assistance can contact the ACSC via 1300 CYBER1 (1300 292 371).

Image credit: iStock.com/amgun

Related News

ACSC updates guidance on detecting and mitigating AD compromises

The Australian Cyber Security Centre has released updated guidance on detecting and mitigating...

Splunk advancements help deliver trusted AI on premises

Splunk AI features are now available on‍-‍premises with the release of Cisco AI POD...

Citadel Edge and Cyber Automation announce strategic partnership

Two Australian cybersecurity companies have announced a partnership that they say is to help...


  • All content Copyright © 2026 Westwick-Farrow Pty Ltd