ACSC warns of actively exploited vulnerabilities in Citrix NetScaler products – Australian Cyber Security Magazine

ACSC warns of actively exploited vulnerabilities in Citrix NetScaler products – Australian Cyber Security Magazine

By Editorial Team
Publication Date: 2026-09-28 00:35:00


The Australian Cyber Security Centre (ACSC) has issued a critical alert for Australian organisations running Citrix NetScaler ADC and Citrix NetScaler Gateway, warning of multiple newly disclosed vulnerabilities and urging customers to apply vendor updates.

In an alert dated 28 September 2026, the ACSC said Citrix had released details of eight vulnerabilities affecting the products. The ACSC said it understood at least two of the flaws had been under active exploitation globally before a patch was available, though it had not received reports of confirmed exploitation in Australia.

One of the vulnerabilities, CVE-2026-88771, was described as a remote code execution issue that could allow an unauthenticated attacker to execute arbitrary commands. The ACSC said all configurations of Citrix NetScaler ADC and Citrix NetScaler Gateway were affected by that vulnerability.

The ACSC said the remaining seven vulnerabilities…