
Citrix is urging organisations to update customer-managed NetScaler ADC and NetScaler Gateway appliances after confirming that two newly disclosed vulnerabilities are being exploited. These are internet-facing systems in many enterprise networks, so the difference between a patch available and a patch installed matters immediately.
The company’s September 27 security bulletin covers eight flaws in all. It says CVE-2026-88771 and CVE-2026-88772 have been observed in active exploitation. Both carry a CVSS v4 score of 9.5 and can potentially lead to remote code execution. Citrix says the first affects default deployments, while the second concerns systems with DTLS enabled, which is the default on VPN virtual servers.
Administrators should first identify which NetScaler versions they operate and whether the devices are exposed to the internet. Citrix lists fixed releases including NetScaler 14.1-73.37 and 13.1-64.23 or later, with separate fixes for applicable FIPS builds. The company’s technical guidance provides indicators and further response advice. Citrix-managed cloud services are being updated by Citrix, but customers running their own appliances must apply the fixes themselves.
Patching is only the first step when exploitation has already been observed. Security teams should review logs and the vendor’s indicators for signs that a device was targeted before it was updated. A clean patch record does not, by itself, establish that an exposed appliance was never compromised.
The risk is familiar from earlier attacks on perimeter infrastructure. A gateway is built to let trusted users into a network. When attackers can take control of that gateway, they may gain a position much closer to internal systems than an ordinary compromised web page would allow.
For businesses using NetScaler, this is not a story to file for the next maintenance window. Confirm the build, apply the vendor’s fix and investigate suspicious activity on any appliance that was reachable while vulnerable. Those three actions matter more than the headline severity score alone.







