Citrix has disclosed multiple critical vulnerabilities affecting its NetScaler ADC and Gateway products, with at least two of these vulnerabilities, CVE-2026-88771 and CVE-2026-88772, reportedly under active exploitation globally. The Australian Cyber Security Centre (ACSC) has not confirmed any exploitation within Australia as of now.
MIDDLE EAST RELEVANCE
While the vulnerabilities primarily affect Australian organizations, the Citrix NetScaler products are also utilized by various entities in the Middle East. Organizations in the UAE and GCC that operate these products should assess their configurations and security measures in light of these vulnerabilities.
KEY FACTS
- Citrix has identified eight new vulnerabilities in its NetScaler ADC and Gateway products.
- CVE-2026-88771 allows for Remote Code Execution by unauthenticated attackers.
- At least two vulnerabilities are actively exploited globally, but no confirmed cases in Australia have been reported.
- Other vulnerabilities require specific configurations to be exploitable.
- Organizations are advised to review their device configurations against the vulnerabilities.
TECHNICAL CONTEXT
CVE-2026-88771 is a critical Remote Code Execution vulnerability that affects all configurations of Citrix NetScaler ADC and Gateway products, allowing attackers to execute arbitrary commands without authentication. The remaining vulnerabilities require specific configurations to be vulnerable, and Citrix has provided guidance for organizations to assess their exposure to these risks.
RISK AND DECISION
Organizations using Citrix NetScaler products in the Middle East should prioritize reviewing their configurations and applying the necessary security updates. The potential for exploitation of these vulnerabilities poses significant operational risks, including unauthorized access and data breaches. It is crucial for IT security teams to act promptly to mitigate these risks and ensure compliance with security best practices.
DEFENSIVE GUIDANCE
Organizations operating vulnerable Citrix products should review the details of the vulnerabilities and install the recommended security updates. It is also advisable to conduct internal security assessments to prioritize the implementation of these updates effectively. Additionally, organizations should monitor device logs for any suspicious activity that may indicate exploitation attempts.
Source and evidence
This report is based on an advisory from the Australian Cyber Security Centre (ACSC) regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, published on the ACSC website.
CWME will continue tracking regional implications as more verified information becomes available.
Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.


