The Security Briefing

NetScaler Attacks Went Undetected in Australia for Three Weeks

Written by Karyee Lee | Oct 7 2026

Three weeks. That's how long attackers were already inside Australian organisations running Citrix NetScaler before anyone outside the intrusion knew there was a vulnerability to find, let alone patch.

On 28 September, the Australian Signals Directorate's Cyber Security Centre (ACSC) confirmed active exploitation of two critical NetScaler flaws against Australian organisations, dating back to at least 4 September. Citrix didn't disclose or patch the vulnerabilities until 27 September, which means the attackers had three weeks of uninterrupted access before most security teams had any reason to look for them.

For any organisation running NetScaler ADC or NetScaler Gateway for remote access or application delivery, this is not a routine patch advisory. It's a reminder that a vulnerability can be exploited quietly, at scale, long before it has a name, a patch or a place on anyone's risk register.

What happened

The ACSC's alert concerns two vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway: CVE-2026-88771 and CVE-2026-88772. Both carry a CVSS severity score of 9.5 out of 10, among the highest ratings the scoring system allows.

CVE-2026-88771 is an unauthenticated remote code execution flaw affecting NetScaler appliances in their default configuration, meaning no special setup is required for an attacker to exploit it. CVE-2026-88772 is a memory overflow vulnerability affecting appliances with DTLS enabled, which happens to be the default configuration for NetScaler devices acting as VPN servers. In practice, that covers a large share of the organisations using NetScaler for remote access.

Citrix disclosed both vulnerabilities and released patches on 27 September. The US Cybersecurity and Infrastructure Security Agency (CISA) added them to its Known Exploited Vulnerabilities catalogue the same day and ordered US federal civilian agencies to patch within days. Cyber Daily reported on 1 October that the ACSC had already confirmed multiple Australian organisations compromised by the time the patch became available, with attackers deploying a Perl script that establishes a persistent TCP listener and system check-in capability, built for long-term access rather than a single smash-and-grab intrusion.

The three-week blind spot

What makes this incident worth more than a routine patch reminder is the timeline. Threat-intelligence firm GreyNoise first detected exploitation attempts on 24 September, three days before Citrix's public disclosure. The ACSC's own alert states that the campaign against Australian organisations had been running since at least 4 September, which means this was a genuine zero-day: a vulnerability actively exploited in the real world for roughly three weeks before it was publicly known to exist.

Once Citrix disclosed the flaws, security research firm watchTowr Labs published a root-cause analysis and proof-of-concept on 28 September. That tipped the campaign from a quiet, targeted operation into mass, automated scanning across the internet, as other attackers rushed to exploit unpatched systems before they could be fixed.

Security researcher Kevin Beaumont has described the early activity as closer to espionage than opportunistic cybercrime, noting that each compromised system was left with its own unique webshell, a piece of code that lets an attacker back in later. Because each one is different, it can't be found by scanning for a known signature from the outside. Only the attacker who planted it knows exactly where to look.

Why patching alone is not enough

Applying Citrix's patch closes the door the attackers used to get in. It doesn't answer the harder question: did anyone already walk through it between 4 and 27 September.

For any Australian organisation running NetScaler ADC or NetScaler Gateway, particularly for VPN access, the practical response has two parts. The first is the patch itself, which should already be done. The second, easy to skip under pressure, is a retrospective check: reviewing logs and system activity back to early September for signs of compromise that predate the public disclosure, not just from the moment the alert landed. Citrix has published indicators of compromise alongside its advisory, and the ACSC's alert sets out the detection steps it recommends.

This matters because the usual working assumption, that a system is safe once it's patched, doesn't hold for a genuine zero-day. An attacker who established persistent access during the unpatched window can still be sitting inside a system that has since been fully updated.

A familiar way in

This is not the first time a NetScaler vulnerability has been the entry point for a significant Australian incident. In 2023, a Citrix NetScaler flaw was the route attackers used to breach DP World Australia, disrupting operations at the company's ports and showing how a single unpatched appliance can have consequences well beyond IT.

That repetition is worth naming rather than treating each new NetScaler advisory as an isolated event. Appliances like NetScaler sit at the edge of a network, handling remote access and traffic between the public internet and internal systems, which makes them a consistently attractive target. An organisation's patching discipline for these specific, internet-facing systems deserves more scrutiny than it typically gets, not less.

What this means for Australian security teams

This isn't only a problem for IT security teams. Organisations in critical infrastructure, retail, transport and government rely on remote-access infrastructure like NetScaler to keep operations running, and an undetected intrusion there is an operational risk as much as a technical one, with the potential to disrupt services long before any data loss becomes apparent.

For security leaders without a technical background in network appliances, the useful question to ask an IT or security operations team this week isn't just whether the patch has been applied. It's whether anyone has checked for compromise that happened before the patch existed, and whether that check has actually been done, not just scheduled.

A further NetScaler vulnerability, CVE-2026-88779, a denial-of-service flaw, was disclosed in the days since, with CISA setting another patch deadline this week. This story is still moving, and worth checking again rather than treating as closed once the first patch is applied.

Related reading

This isn't the only recent story about the gap between when something goes wrong and when anyone finds out. The Security Briefing's reporting on OpenAI's Medicare breach covered a different kind of vendor failure: a three-month delay between discovery and disclosure, rather than a technical exploit. Our recent piece on connected vehicles and the expanding security perimeter looked at a related theme: how the definition of an organisation's attack surface keeps growing into places security teams haven't traditionally looked:  The Car Park Is Now Part of the Perimeter: What the Four Corners EV Investigation Found

Register for The Security Event Australia happening  25-26 November 2026, MCEC Melbourne

Subscribe to The Security Briefing for monthly updates!