ACSC warns of confirmed exploitation of Citrix NetScaler vulnerabilities – Australian Cyber Security Magazine

ACSC warns of confirmed exploitation of Citrix NetScaler vulnerabilities – Australian Cyber Security Magazine

By Editorial Team
Publication Date: 2026-10-01 00:52:00


The Australian Cyber Security Centre (ACSC) has issued an updated critical alert on vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway, saying it has received reports from Australian organisations confirming exploitation.

The ACSC, part of the Australian Signals Directorate (ASD), said organisations should review for evidence of compromise dating back to at least 4 September 2026. The update follows an initial ACSC alert published on 28 September 2026.

Citrix has disclosed eight vulnerabilities in the products and published guidance in a security bulletin covering CVE-2026-88771 through CVE-2026-88778. The ACSC said Citrix has also made indicators of compromise available through NetScaler Console.

According to the ACSC, at least two of the vulnerabilities—CVE-2026-88771 and CVE-2026-88772—were under active exploitation globally before a patch became available. In the alert’s background…