Leadership2 publishers2 min readPublished
Two NetScaler zero-days under active attack justify an outage outside the patch cycle
Citrix has patched eight NetScaler flaws, including two zero-days scored 9.5 that CISA says attackers are exploiting globally. The safest response costs a planned outage of remote access now and months of monitoring afterwards.
The Board Room · Leadership desk

What happened
- CVE-2026-88771 affects every NetScaler ADC and Gateway deployment, including default configurations, and needs no additional feature switched on to be exploitable.
- CVE-2026-88772 requires DTLS, and Citrix says DTLS is on by default on VPN virtual servers, so the flaw reaches many Gateway deployments.
- watchTowr reported that both flaws were exploited before fixes were available, and Citrix said it had seen exploitation on unmitigated deployments.
- CISA added both exploited flaws to its Known Exploited Vulnerabilities catalog on Sunday.
- The other six fixes matter only under specific configurations, led by a 9.3-rated HTTP request-smuggling flaw affecting HTTP and SSL virtual servers.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- decision Following NCSC guidance means scheduling a remote-access outage this week; deferring to the normal window means running a known-exploited gateway until then.
- cost The patch is the cheap step. A compromise hunt and at least 90 days of close monitoring put the larger cost into next quarter's security budget.
- exposure According to ColorTokens' Sarkar, an intruder on the appliance can pivot toward Active Directory, so a compromise reaches well beyond the gateway itself.
- precedent With four critical NetScaler flaws patched in about a month, an out-of-cycle procedure with a pre-agreed outage budget is now a standing need for these appliances.
The board-deck version of this advisory fits on one line: move every NetScaler appliance to the fixed builds Citrix has released, 14.1-73.37 or 13.1-64.23 and later [14]. That line is incomplete where the cost sits. "It is also imperative to know that patching does not remove an existing webshell that has been placed on a compromised device," said Mayuresh Dani, security research manager at Qualys [10].
The trade-off is availability against exposure, and the UK's National Cyber Security Centre states it openly. Its advice is to isolate affected systems and replace them with new, fully up-to-date ones [8]. The NCSC also warns that this may cause a service outage, because it could mean cutting access at upstream firewalls, disabling the vulnerable components, or limiting access to the organization's own IP range [8]. NetScaler appliances provide VPN and remote access in many enterprise networks [15].
A skeptic running operations would say the outage is certain while the breach is only probable, and that the regular maintenance window is close enough. Benjamin Harris, chief executive of watchTowr, had answered that by Sunday. "Monday will be too late," he wrote on LinkedIn [12]. The NCSC expects exploitation attempts to increase now that patches and technical details are public [7]. Citrix told customers to install the fixed versions "as soon as possible" [21]. I think the planned outage is the cheaper of the two costs.
Sequencing is simpler than eight CVE numbers suggest. "Based on the available CVSS scores, exploiting CVE-2026-88772 is more difficult than CVE-2026-88771," Dani said [9]. That gap does not change the order of work. CISA said both flaws "can independently enable remote code execution" [5], and the same builds close both [14]. A VPN virtual server in its default configuration is exposed to both [1]. Those appliances come first.
The spending that follows lands in next quarter. Dani read Citrix's recommendation to forward NetScaler logs to an external logging or SIEM platform as a sign that attackers can maintain persistence and alter vulnerable devices [11]. He said the devices should stay under strict observation for at least 90 days [11]. Agnidipta Sarkar, chief evangelist at ColorTokens, described what an intruder expecting discovery would do in the meantime. "Since most attackers here will expect discovery, they might silently harvest credentials, especially VPN credentials, exfiltrate existing business data or any other data that is immediately available," he said [17].
The sources do not say how many appliances were compromised before the fixes shipped. Citrix has made generic indicators of compromise available through NetScaler Console so customers can check their own appliances [20].
What to watch
- A public proof-of-concept for either flaw; Qualys said none was available yet, and one would widen the pool of attackers able to use them.
- Victim disclosures or matches against Citrix's generic indicators of compromise, which would show how many appliances were entered before the fixes.
- Another Citrix NetScaler advisory in the coming weeks, which would confirm a pattern of repeated critical fixes on these appliances.