Government Advisory

Urgent: Citrix NetScaler Devices Under Active Attack, Patch Immediately

CISA · 27 Sept 2026
Key Takeaway If your business runs Citrix NetScaler ADC or Gateway, check for compromise indicators immediately and patch as a top priority, since attackers are actively exploiting these flaws worldwide.

CISA has issued an alert on eight newly disclosed vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway products, which are widely used to manage secure remote access and network traffic. Two of these flaws, CVE-2026-88771 and CVE-2026-88772, have been added to CISA's Known Exploited Vulnerabilities catalog. Both are critical, zero-day issues that can independently allow attackers to remotely take control of affected systems, and CISA has confirmed active exploitation occurring globally.

Because patching NetScaler appliances can require downtime and careful planning, CISA is urging organisations to review Citrix's advisories now and prioritise remediation. Businesses are also encouraged to check for signs of compromise before applying updates, since patching can erase forensic evidence needed to investigate a breach. Citrix has released indicators of compromise and additional guidance to help organisations assess whether their systems have already been affected.

Any Australian business using Citrix NetScaler ADC or Gateway devices, common in organisations providing remote access to staff, should treat this as an urgent priority given confirmed real-world exploitation.

Citrix NetScaler vulnerability CISA remote access

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.