New NetScaler SAML issue affects Australian organisations: ask your IT provider to check
ACSC reports Australian impacts from a new NetScaler SAML authentication issue. Check affected configurations with your IT provider while Citrix prepares an update.

Australian businesses whose IT provider uses Citrix NetScaler should ask for a fresh configuration check. ASD’s Australian Cyber Security Centre updated its alert on 3 October with a newly identified SAML authentication issue and says it is aware of impacts to Australian organisations.
For an owner or office manager, the practical first step is to forward that alert to the person responsible for the business’s IT. Our recommendation is to request a specific assessment today, especially if someone has already reassured you that recent NetScaler updates were installed.
Check which issue the provider assessed
Citrix’s guidance describes a configuration-dependent issue involving customer-managed NetScaler Gateway or AAA virtual servers with SAML authentication. It says the issue is independent of the vulnerabilities in its earlier bulletin, CTX697096.
That distinction should appear in your provider’s reply. Our suggested question is: “Do any services supporting our business use this NetScaler configuration, and have you assessed the new SAML issue separately from the earlier vulnerabilities?” Ask whoever manages the equipment to answer, even if your usual support contact needs to pass the question on.
ACSC says a remote attacker exploiting the new issue may cause crashes, denial of service and potential exploitation. Its advice is to review configurations, watch for unusual activity and follow Citrix’s guidance. Impacted organisations are encouraged to contact Citrix support and report to ACSC.
A new update is planned
The Citrix guidance checked for this article was last updated on 2 October, Pacific Daylight Time. It says a new security bulletin and simultaneous product update are planned. It directs affected customers to upgrade as soon as possible once the bulletin is published.
The checked guidance does not establish a released fix for this new issue. Avoid treating a previous patch confirmation as the answer. Our recommendation is to ask the provider who will follow the announcement, assess the applicable release and tell you when the work has been completed.
You do not need to interpret appliance settings yourself. Give the provider the official links and ask it to explain the finding in business terms: whether your services are affected, what it has checked, and what happens next. If it proposes changes that could interrupt work, ask about the likely disruption and how staff should prepare.
Keep the incident questions separate
The ACSC alert also contains earlier updates about different NetScaler vulnerabilities. Its 30 September update confirmed Australian exploitation and recommended checking for compromise since at least 4 September. Those dates concern the earlier vulnerabilities; they are not a confirmed start date for the new SAML issue.
Our recommendation is to keep a short written record of the provider’s assessment and next update. If it reports a suspected incident, ask who owns the response and what evidence is available about your business’s services. Our business email first-hour guide covers business-side steps if email accounts are affected; the Scams & security hub collects related guidance.
Checklist
- Ask your IT provider today. Find out whether services supporting your business use the NetScaler configuration described in Citrix’s new SAML guidance.
- Request a separate assessment. Have the provider distinguish this issue from the vulnerabilities covered by the earlier bulletin.
- Confirm monitoring and escalation. Ask who is checking for unusual activity and who will contact Citrix support and ACSC if impact is suspected.
- Assign the update follow-through. Get a named provider contact to track the new bulletin and arrange any applicable upgrade when released.
- Keep the result in writing. Record the assessment, any proposed service interruption and the provider’s next update.
Tick items as you go. Your ticks stay in this browser.




