Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Act Now! ACSC & CISA urge immediate action over raft of new Citrix NetScaler ADC & Gateway vulnerabilities

Experts are aware of active exploitation of at least two of the vulnerabilities; customers are advised to “take the appliances offline immediately”.

• Mon, 28 Sep 2026 •
Act Now! ACSC & CISA urge immediate action over raft of new Citrix NetScaler ADC & Gateway vulnerabilities

Cloud computing firm Citrix’s Cyber Threat Intelligence Team issued a security update overnight disclosing eight vulnerabilities in its NetScaler ADC and NetScaler Gateway products, and government cyber agencies wasted no time in amplifying the warning.

“Citrix has released updates for NetScaler ADC and NetScaler Gateway to address multiple security vulnerabilities,” the company said in a September 28 advisory.

“These vulnerabilities vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions.”

 
 

Unfortunately, two of them – CVE-2026-88771 and CVE-2026-88772 – are already drawing the wrong sort of attention, with Citrix observing exploitation on “unmitigated NetScaler deployments”.

“Citrix strongly urges affected customers to install the relevant updated versions as soon as possible,” Citrix said.

The United States Cybersecurity & Infrastructure Security Agency circulated its own warning not long after, and the Australian Signals Directorate’s Australian Cyber Security Centre issued its own Critical Alert this morning.

“ASD's ACSC recommends that organisations operating vulnerable Citrix products review details of the vulnerabilities released by the vendor and install the security update,” the ACSC said.

“Organisations should consider internal security assessments and business plans, in determining how to effectively prioritise the implementation of this security update.”

The agency said organisations using affected versions should study the “pre-condition requirements for each of the CVEs to understand where they may have been vulnerable to exploitation,” the ACSC said.

“ASD's ACSC recommends reviewing device logging for any suspicious activity, which is consistent with the kinds of attacks enabled by each of the CVE’s where the pre-conditions for exploitation have been met.”

CISA went a step further and recommended that any organisations suspicious of potential compromises “preserve forensic evidence prior to applying updates, as updates may result in loss of forensic visibility”.

The vulnerabilities impact the following products and versions:

  • NetScaler ADC and NetScaler Gateway 14.1-73.37 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-64.23 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

The CVSS scores of the vulnerabilities range from 8.8 to 9.5, and full details, mitigation advice, and Indicators of Compromise can be found here.

Benjamin Harris, Founder and CEO of exposure management firm watchTowr, said that NetScaler administrators were unlikely to find much rest over the coming 24 hours.

“Guidance to organisations leveraging Citrix NetScalers in their environments is extremely clear: take the appliances offline immediately,” Harris told Cyber Daily.

“Unfortunately, as of now, there is no official communication from Citrix publicly but as always, Citrix and your national CERT will remain the best source of information related to this threat as the situation evolves.

“There should be no ambiguity here. This is a serious situation and should not be underestimated. Teams responsible for looking after Citrix NetScaler need to act now - waiting until Monday will be too late.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: