Citrix NetScaler Under Attack: What Perth Businesses Must Check Now

The ACSC has confirmed Australian organisations are being compromised through Citrix NetScaler flaws. Here is what Perth businesses should check, patch and review this week. From Computer Mechanics, Perth IT specialists since 1997.

Garry BloomGarry Bloom · Founder & CEO
2 October 2026
5 min read
Cybersecurity
Firewall
Patching
Perth Business
Network firewall and gateway security management for a Perth business

If your business uses a Citrix NetScaler ADC or NetScaler Gateway for remote access, patch it now and check it for signs of compromise. On 1 October 2026 the Australian Cyber Security Centre (ACSC) issued a critical alert after Australian organisations confirmed exploitation of two NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88778. The ACSC recommends reviewing for evidence of compromise going back to at least 4 September 2026, so patching alone is not enough.

What has been reported

Per the reporting on the ACSC alert, CVE-2026-88771 is a remote code execution flaw. An unauthenticated attacker can run commands on the device, and every configuration of NetScaler ADC and Gateway is affected by it.

Observed attacker activity included:

  • Command injection, followed by downloading a payload
  • Script execution and tests to confirm commands were running
  • Reverse-shell attempts back to the attacker
  • Perl-based persistence tools that open listeners and keep access after a reboot

Security researchers quoted in the coverage assess the campaign as espionage-focused rather than ordinary criminal activity, with more than 100 victim organisations identified. That does not make smaller businesses safe. Attackers scan the whole internet for vulnerable devices, and a compromised gateway is a doorway into whatever sits behind it.

Which versions are affected

Update to at least these builds, which are the fixed versions listed in the alert coverage:

  • NetScaler ADC and Gateway 14.1-73.37 or later
  • NetScaler ADC and Gateway 13.1-64.23 or later
  • NetScaler ADC FIPS 14.1-73.37 FIPS or later
  • NetScaler ADC FIPS and NDcPP 13.1-37.279 or later

Always confirm the exact build numbers against Citrix's own advisory and the ACSC alert before you act, as versions can be revised.

Do I even have a NetScaler?

Many small businesses do not know. A NetScaler is sometimes installed by a previous IT provider to publish remote desktop, a Citrix Virtual Apps environment or a VPN. Ask these questions:

  1. Does anyone log in to a Citrix or "NetScaler" web page to reach desktops or apps from home?
  2. Does an invoice or asset register list NetScaler, Citrix ADC or Citrix Gateway?
  3. Does your IT provider manage a virtual or physical appliance at the edge of your network?

If you are unsure, ask your IT provider in writing. "We don't think so" is not an answer to accept for a device that faces the internet.

Patching is step one, not the finish line

Because exploitation reportedly began as early as 4 September, an attacker may already be inside a device you have only just patched. Updating closes the hole but does not remove a persistence tool left behind. A sensible response has four parts:

  • Patch to a fixed build as an emergency change, not at the next maintenance window.
  • Review device logs, running processes and files from 4 September onward for unfamiliar scripts, listeners or outbound connections.
  • Rotate credentials that passed through the device, including service accounts and any VPN or directory-bind passwords.
  • Escalate to an incident process if anything looks wrong. Do not just reboot, as that can destroy evidence.

This is the same pattern we covered in our posts on the Check Point VPN flaw and on firewall vulnerabilities in September: the device that guards your network is itself a target, and it needs the same patching discipline as your servers.

What to tell your leadership team

Boards and owners do not need the CVE detail. They need three plain answers from whoever looks after your IT: do we run an affected device, has it been patched, and has it been checked for compromise since early September? Ask for those answers in writing, with dates. If your business holds client, patient or financial records, a compromised gateway can also trigger notification obligations under the Notifiable Data Breaches scheme, so it is far better to find out now than to be told by someone else later.

Also check that your backups are separate from the network the gateway protects. If an attacker does get in, offline or immutable copies are what let you recover without negotiating.

Reduce your exposure for next time

Edge devices will keep being attacked. A few habits limit the damage:

  • Keep an inventory of every internet-facing device and who is responsible for patching it.
  • Subscribe to ACSC alerts so a critical advisory reaches a person, not a spam folder.
  • Put multi-factor authentication in front of remote access, and avoid exposing management interfaces to the internet.
  • Consider whether you still need the appliance at all. Some businesses can retire an ageing gateway in favour of a modern, managed approach. Our firewall service page explains how we handle this.

Need a hand?

If you use NetScaler, or are not sure whether you do, we can identify your internet-facing devices, confirm patch levels and check for the signs the ACSC describes. Our IT security solutions are delivered from Perth, and we have been helping local businesses since 1997. Call (08) 9325 1196 and ask for a check of your remote-access setup.

Garry Bloom
Written by
Garry Bloom
Founder & CEO · 29 years in IT

Garry founded Computer Mechanics — the business behind IT Support Perth — in 1997. With 29 years in IT management and support across internal and external service environments, he leads the team's technical direction and its cybersecurity and managed-IT strategy for Perth businesses.

Meet the IT Support Perth team →
Garry Bloom
2 October 2026
5 min read
Cybersecurity
Firewall
Patching
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

Exchange, Office 2021 and Windows Server 2012 All Lose Support in October 2026: Perth Guide

Exchange 2016/2019, Office 2021 and Windows Server 2012 all stop receiving security updates in October 2026. Here's what Perth businesses running any of them need to do before then. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

SonicWall's Remote-Access Gateway Just Scored a Perfect 10: What Perth Businesses Should Check

Two chained SonicWall SMA1000 flaws let an attacker take over the appliance without a password, and they're being exploited now. Here's what Perth businesses with remote staff should do this week. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Ransomware Gangs Are Naming Ordinary Australian Businesses: What Perth SMBs Should Do Now

Three ransomware groups have claimed attacks on ordinary Australian businesses in September 2026 — not banks or hospitals. Here's why Perth SMBs need an incident response plan before it happens, not after. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

Cybersecurity
Firewall

SonicWall's Remote-Access Gateway Just Scored a Perfect 10: What Perth Businesses Should Check

Two chained SonicWall SMA1000 flaws let an attacker take over the appliance without a password, and they're being exploited now. Here's what Perth businesses with remote staff should do this week. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
9/25/2026
Cybersecurity
Firewall

Critical Flaw in Check Point's Small-Business Firewall: What to Patch This Week

Check Point has patched two critical, unauthenticated RCE flaws (CVSS 9.8) in its VPN gateways, including the Spark Firewall used by many small offices. Here's what Perth businesses should check. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
9/21/2026
Cybersecurity
Ransomware

Ransomware Gangs Are Naming Ordinary Australian Businesses: What Perth SMBs Should Do Now

Three ransomware groups have claimed attacks on ordinary Australian businesses in September 2026 — not banks or hospitals. Here's why Perth SMBs need an incident response plan before it happens, not after. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
9/23/2026