Skip to content
Critical Vulnerabilities in Citrix NetScaler Targeting Australian Organizations

Critical Vulnerabilities in Citrix NetScaler Targeting Australian Organizations

First seen 1 Oct 2026, 03:02 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 03:03 UTC
  • •Two critical vulnerabilities in Citrix NetScaler products are actively exploited.
  • •CVE-2026-88771 and CVE-2026-88778 have CVSS scores of 9.5 and 8.8, respectively.
  • •Australian organizations are urged to review for signs of compromise and apply security updates.

The Australian Cyber Security Centre (ACSC) has issued a critical alert regarding exploitation of two vulnerabilities in Citrix NetScaler ADC and Gateway products. Reports indicate that Australian organizations have been targeted since at least September 4, 2026. The vulnerabilities, CVE-2026-88771 (remote code execution, CVSS 9.5) and CVE-2026-88778 (TCP ISN prediction, CVSS 8.8), were disclosed on September 27, 2026. Cybersecurity firm Arctic Wolf has observed malicious activities including command injection and reverse-shell attempts. Experts suggest that the motives behind these attacks may be espionage rather than criminal. Organizations are advised to review their systems for evidence of compromise and apply the necessary security updates. Citrix has provided indicators of compromise and additional guidance for affected products.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-27
Citrix vulnerabilities disclosed
Citrix announced CVE-2026-88771 and CVE-2026-88778, both critical vulnerabilities affecting NetScaler products.
Cybersecurityconnect.Au
2026-09-27
CVE-2026-88771 added to CISA KEV
CVE-2026-88771 was added to the CISA Known Exploited Vulnerabilities catalog due to active exploitation.
Cyberdaily.Au
2026-09-27
CVE-2026-88778 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-28
First public PoC released
Proof-of-concept code for CVE-2026-88771 was made publicly available, increasing the risk of exploitation.
Cybersecurityconnect.Au
2026-10-01
ACSC issues critical alert
The ACSC confirmed ongoing exploitation of the vulnerabilities and advised organizations to assess for compromise.
Cyberdaily.Au

More articles in this cluster (2)

Following this threat?

Track CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which Citrix products are affected?
Citrix NetScaler ADC and Citrix NetScaler Gateway versions 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23 are affected.
What actions should organizations take?
Organizations should review for evidence of compromise, apply security updates, and assess their internal security measures.
Is there confirmed exploitation in the wild?
Yes, exploitation of these vulnerabilities has been confirmed by the ACSC and observed by cybersecurity firms.