Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-29 · updated: 2026-09-29 · tags: [incident, acsc, asd, australia, citrix, netscaler, active-exploitation, critical] · confidence: high · severity: critical · affected_sectors: [government, technology] · au_impact: true

ACSC Critical Alert — Citrix NetScaler ADC and NetScaler Gateway (2026-09-28)

ASD's Australian Cyber Security Centre (ACSC) issued a Critical-rated alert on 28 September 2026 covering eight new vulnerabilities Citrix released for NetScaler ADC and NetScaler Gateway. The ACSC states it understands that at least two — CVE-2026-88771 and CVE-2026-88772 — "have been under active exploitation globally prior to a patch becoming available", while noting it has not yet received reports of confirmed exploitation in Australia.

Overview

Attribute Detail
Publisher ASD's Australian Cyber Security Centre
Published 2026-09-28
Alert rating Critical
CVEs CVE-2026-88771, CVE-2026-88772 (of eight: CVE-2026-88771 → CVE-2026-88778)
Product Citrix NetScaler ADC and NetScaler Gateway (customer-managed deployments)
Audience Small & medium business; large organisations & critical infrastructure; government
Source ACSC alert

ACSC guidance

  1. Review the vendor bulletin (CTX697096) and install the security update, prioritising it against internal security assessments and business plans.
  2. Review the pre-condition requirements for each of the eight CVEs to understand where the organisation may have been vulnerable to exploitation.
  3. Review device logging for suspicious activity consistent with attacks enabled by each CVE where exploitation pre-conditions were met.

Significance

The ACSC alert is the operative action for Australian organisations running NetScaler appliances, and it co-seals a campaign that CISA added to the Known Exploited Vulnerabilities catalogue on 27 September with a US federal patch deadline of Wednesday 30 September. CVE-2026-88771 requires no special configuration — the ACSC states all configurations of NetScaler ADC and NetScaler Gateway are affected — while the remaining seven require particular configurations to be in place. NetScaler appliances are internet-facing edge devices providing remote access and application delivery, so a compromise yields a perimeter foothold inside the network without requiring an endpoint to be breached. The same appliances and builds are in use in New Zealand, so the advisory reads across the Tasman directly.

Related