Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-05 · updated: 2026-10-05 · tags: [incident, government] · confidence: high · severity: critical · affected_sectors: [government] · au_impact: true

ASD's ACSC updated its Citrix NetScaler alert on 3 October with a new section covering the SAML authentication flaw, records that "a remote attacker exploiting the issue may induce system crashes, denial of service and potential exploitation", and states that "ASD's ACSC is aware of impacts to Australian organisations." The update keeps the SAML issue explicitly separate from the CVE-2026-88771 and CVE-2026-88772 vulnerabilities that prompted the original 28 September alert, and directs organisations using NetScaler SAML authentication to review configurations, monitor for unusual activity, follow Citrix's guidance, contact Citrix support and report to ACSC. The alert remains rated critical and is written for small and medium business, large organisations and infrastructure, and government; the 30 September update's advice to review for evidence of compromise since at least 4 September 2026 still stands. For Australian operators the material point is scope: the population affected is defined by whether SAML is configured, not by whether the appliance was already patched in the September cycle.

Attribute Detail
Sector Government
Date 2026-10-05
Source ASD's ACSC — Critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway products
Reliability Tier 1
CVEs CVE-2026-88771, CVE-2026-88772