The Australian Cyber Security Centre (ACSC) has issued an updated critical alert on vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway, saying it has received reports from Australian organisations confirming exploitation.
The ACSC, part of the Australian Signals Directorate (ASD), said organisations should review for evidence of compromise dating back to at least 4 September 2026. The update follows an initial ACSC alert published on 28 September 2026.
Citrix has disclosed eight vulnerabilities in the products and published guidance in a security bulletin covering CVE-2026-88771 through CVE-2026-88778. The ACSC said Citrix has also made indicators of compromise available through NetScaler Console.
According to the ACSC, at least two of the vulnerabilities—CVE-2026-88771 and CVE-2026-88772—were under active exploitation globally before a patch became available. In the alert’s background section, the ACSC said it had not yet received reports of confirmed exploitation in Australia, but the update states it has since received reports from Australian organisations confirming exploitation.
The ACSC described CVE-2026-88771 as a remote code execution vulnerability that can allow an unauthenticated attacker to execute arbitrary commands. It said all configurations of Citrix NetScaler ADC and Citrix NetScaler Gateway are affected and vulnerable to exploitation against this CVE.
The remaining vulnerabilities require certain configurations for systems to be vulnerable, the ACSC said, noting Citrix has provided instructions for customers to assess exposure for each CVE.
As mitigation, the ACSC recommended that organisations operating vulnerable Citrix products review the vendor’s vulnerability details and apply the security update. It also advised organisations to consider internal security assessments and business plans when prioritising deployment, review pre-condition requirements to understand where they may have been exposed, and check device logging for suspicious activity consistent with attacks enabled by the vulnerabilities.
Organisations seeking assistance can contact the ACSC via 1300 CYBER1 (1300 292 371), the alert said.

