Critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway products
Alert for organisations to implement a high-priority patch addressing new vulnerabilities, under active exploitation in Citrix NetScaler ADC and Citrix NetScaler Gateway products.
- Published
-
- Last reviewed
-
Recent update
3 October 2026
Citrix has published guidance about a newly identified issue affecting NetScaler ADC and NetScaler Gateway deployments that use SAML authentication.
A remote attacker exploiting the issue may induce system crashes, denial of service and potential exploitation.
ASD’s ACSC is aware of impacts to Australian organisations.
Organisations using NetScaler SAML authentication should review their configurations, monitor for unusual activity, and follow Citrix advice.
Organisations impacted by this issue are also encouraged to contact Citrix support and report to ASD’s ACSC.
This issue is understood to be separate from the vulnerabilities outlined below [CVE-2026-88771 and CVE-2026-88772].
30 September 2026
Since publishing the alert on 28 September 2026, the Australian Signals Directorate's Australian Cyber Security Centre (ASD’s ACSC) has received reports from Australian organisations confirming exploitation. ASD's ACSC recommends reviewing for evidence of compromise since at least 4 September 2026. Citrix has made indicators of compromise available through NetScaler Console and published additional guidance in their recent publication, Security Bulletin for CVE-2026-88771 through CVE-2026-88778.
This alert is relevant to all Australian organisations who operate Citrix NetScaler ADC and Citrix NetScaler Gateway products.
Background
Citrix has released 8 new vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway products.
ASD's ACSC understands that at least 2 of these vulnerabilities (CVE-2026-88771 and CVE-2026-88772) have been under active exploitation globally prior to a patch becoming available. ASD’s ACSC has not yet received reports of confirmed exploitation in Australia.
CVE-2026-88771 is a Remote Code Execution vulnerability, which can allow an unauthenticated attacker to execute arbitrary commands. All configurations of Citrix NetScaler ADC and Citrix NetScaler Gateway are affected and are vulnerable to exploitation against this CVE.
The remaining 7 vulnerabilities require certain configurations to be in place for the device to be vulnerable to exploitation. Citrix has provided instructions for customers to check to see if their device is vulnerable to each of the other 7 CVEs.
Mitigation advice
ASD's ACSC recommends that organisations operating vulnerable Citrix products, review details of the vulnerabilities released by the vendor and install the security update.
Organisations should consider internal security assessments and business plans, in determining how to effectively prioritise the implementation of this security update.
In addition to applying the security update, organisations should review the pre-condition requirements for each of the CVEs to understand where they may have been vulnerable to exploitation.
ASD's ACSC recommends reviewing device logging for any suspicious activity, which is consistent with the kinds of attacks enabled by each of the CVE’s where the pre-conditions for exploitation have been met.
Where to get help
Organisations that have been impacted, suspect impact or require advice and assistance can contact us via 1300 CYBER1 (1300 292 371)