This alert is relevant to all Australian organisations who operate Citrix NetScaler ADC and Citrix NetScaler Gateway products.
Background
Citrix has released 8 new vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway products.
Australian Signals Directorate's Australian Cyber Security Center (ASD’s ACSC) understands that at least 2 of these vulnerabilities (CVE-2026-88771 and CVE-2026-8872) have been under active exploitation globally prior to a patch becoming available. ASD’s ACSC has not yet received reports of confirmed exploitation in Australia.
CVE-2026-88771 is a Remote Code Execution vulnerability, which can allow an unauthenticated attacker to execute arbitrary commands. All configurations of Citrix NetScaler ADC and Citrix NetScaler Gateway are affected and are vulnerable to exploitation against this CVE.
The remaining 7 vulnerabilities require certain configurations to be in place for the device to be vulnerable to exploitation. Citrix has provided instructions for customers to check to see if their device is vulnerable to each of the other 7 CVE’s.
Mitigation advice
ASD's ACSC recommends that organisations operating vulnerable Citrix products, review details of the vulnerabilities released by the vendor and install the security update.
Organisations should consider internal security assessments and business plans, in determining how to effectively prioritise the implementation of this security update.
In addition to applying the security update, organisations should review the pre-condition requirements for each of the CVEs to understand where they may have been vulnerable to exploitation.
ASD's ACSC recommends reviewing device logging for any suspicious activity, which is consistent with the kinds of attacks enabled by each of the CVE’s where the pre-conditions for exploitation have been met.
Where to get help
Organisations that have been impacted, suspect impact or require advice and assistance can contact us via 1300 CYBER1 (1300 292 371)