If your business uses a Citrix NetScaler ADC or NetScaler Gateway for remote access, patch it now and check it for signs of compromise. On 1 October 2026 the Australian Cyber Security Centre (ACSC) issued a critical alert after Australian organisations confirmed exploitation of two NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88778. The ACSC recommends reviewing for evidence of compromise going back to at least 4 September 2026, so patching alone is not enough.
What has been reported
Per the reporting on the ACSC alert, CVE-2026-88771 is a remote code execution flaw. An unauthenticated attacker can run commands on the device, and every configuration of NetScaler ADC and Gateway is affected by it.
Observed attacker activity included:
- Command injection, followed by downloading a payload
- Script execution and tests to confirm commands were running
- Reverse-shell attempts back to the attacker
- Perl-based persistence tools that open listeners and keep access after a reboot
Security researchers quoted in the coverage assess the campaign as espionage-focused rather than ordinary criminal activity, with more than 100 victim organisations identified. That does not make smaller businesses safe. Attackers scan the whole internet for vulnerable devices, and a compromised gateway is a doorway into whatever sits behind it.
Which versions are affected
Update to at least these builds, which are the fixed versions listed in the alert coverage:
- NetScaler ADC and Gateway 14.1-73.37 or later
- NetScaler ADC and Gateway 13.1-64.23 or later
- NetScaler ADC FIPS 14.1-73.37 FIPS or later
- NetScaler ADC FIPS and NDcPP 13.1-37.279 or later
Always confirm the exact build numbers against Citrix's own advisory and the ACSC alert before you act, as versions can be revised.
Do I even have a NetScaler?
Many small businesses do not know. A NetScaler is sometimes installed by a previous IT provider to publish remote desktop, a Citrix Virtual Apps environment or a VPN. Ask these questions:
- Does anyone log in to a Citrix or "NetScaler" web page to reach desktops or apps from home?
- Does an invoice or asset register list NetScaler, Citrix ADC or Citrix Gateway?
- Does your IT provider manage a virtual or physical appliance at the edge of your network?
If you are unsure, ask your IT provider in writing. "We don't think so" is not an answer to accept for a device that faces the internet.
Patching is step one, not the finish line
Because exploitation reportedly began as early as 4 September, an attacker may already be inside a device you have only just patched. Updating closes the hole but does not remove a persistence tool left behind. A sensible response has four parts:
- Patch to a fixed build as an emergency change, not at the next maintenance window.
- Review device logs, running processes and files from 4 September onward for unfamiliar scripts, listeners or outbound connections.
- Rotate credentials that passed through the device, including service accounts and any VPN or directory-bind passwords.
- Escalate to an incident process if anything looks wrong. Do not just reboot, as that can destroy evidence.
This is the same pattern we covered in our posts on the Check Point VPN flaw and on firewall vulnerabilities in September: the device that guards your network is itself a target, and it needs the same patching discipline as your servers.
What to tell your leadership team
Boards and owners do not need the CVE detail. They need three plain answers from whoever looks after your IT: do we run an affected device, has it been patched, and has it been checked for compromise since early September? Ask for those answers in writing, with dates. If your business holds client, patient or financial records, a compromised gateway can also trigger notification obligations under the Notifiable Data Breaches scheme, so it is far better to find out now than to be told by someone else later.
Also check that your backups are separate from the network the gateway protects. If an attacker does get in, offline or immutable copies are what let you recover without negotiating.
Reduce your exposure for next time
Edge devices will keep being attacked. A few habits limit the damage:
- Keep an inventory of every internet-facing device and who is responsible for patching it.
- Subscribe to ACSC alerts so a critical advisory reaches a person, not a spam folder.
- Put multi-factor authentication in front of remote access, and avoid exposing management interfaces to the internet.
- Consider whether you still need the appliance at all. Some businesses can retire an ageing gateway in favour of a modern, managed approach. Our firewall service page explains how we handle this.
Need a hand?
If you use NetScaler, or are not sure whether you do, we can identify your internet-facing devices, confirm patch levels and check for the signs the ACSC describes. Our IT security solutions are delivered from Perth, and we have been helping local businesses since 1997. Call (08) 9325 1196 and ask for a check of your remote-access setup.
