Introduction
On September 27, 2026, Citrix officially confirmed two zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway — the products that handle load balancing, VPN access, and application traffic control across thousands of enterprise environments. Both flaws, tracked as CVE-2026-88771 and CVE-2026-88772, carry a CVSS score of 9.5 and enable unauthenticated remote code execution. What sets them apart from routine disclosures: they were being actively exploited well before any patch was available.
Two Attack Vectors, One Target
CVE-2026-88771 exploits insufficient input validation, allowing an unauthenticated attacker to execute arbitrary commands on the appliance. No optional feature needs to be enabled — a default installation is sufficient. Every NetScaler ADC or Gateway deployment directly exposed to the internet was a valid target the moment it fell behind on updates.
CVE-2026-88772 involves a memory overflow that can lead to code execution or denial of service. The trigger condition — DTLS protocol enabled — might sound like a narrow edge case. It is not: DTLS is the default configuration for VPN virtual servers in NetScaler Gateway. Virtually every enterprise VPN deployment was vulnerable out of the box, with no configuration changes required. Affected versions include branch 14.1 prior to build 14.1-73.37 and branch 13.1 prior to build 13.1-64.23, including FIPS editions commonly found in regulated environments.
CISA Reverses the Standard Playbook
What makes this incident particularly instructive is the response posture recommended by CISA, which added both CVEs to its Known Exploited Vulnerabilities (KEV) catalog on the same day as the public disclosure. The agency did more than issue an emergency patch directive: it explicitly required organizations to check for indicators of compromise before applying any fix.
The reasoning is sound. On an exposed network appliance, active exploitation leaves artifacts: webshells planted for persistent access, exfiltrated credentials, lateral movement already underway into the internal network. Applying a patch without prior investigation does not close an intrusion that is already in progress — worse, it can destroy the forensic evidence needed to assess the full scope of the breach and notify affected parties. The Netherlands' NCSC-NL underscored this point by pre-alerting targeted organizations before the public disclosure, demonstrating the real operational value of intelligence sharing between national agencies.
A Three-Step Response Plan
The patches released on September 27 — builds 14.1-73.37 and 13.1-64.23 — must be deployed without delay. But applying them alone is insufficient for any appliance that was exposed before that date.
The recommended sequence: first, inspect appliance access logs and look for webshells or anomalous processes; second, review VPN session data and flag suspicious authentications on internal systems reachable through NetScaler Gateway; third, apply the patch only once that analysis has been completed — or formally ruled out based on documented, limited exposure.
A Structural Wake-Up Call for Network Teams
These two zero-days are part of a broader pattern: edge infrastructure — application delivery controllers, VPN gateways, web application firewalls — has become a primary target for threat actors. These devices combine direct internet exposure, elevated privileges over the internal network, and an attack surface that has historically received less scrutiny than endpoints or application servers. For IT and security teams, the conclusion is unavoidable: vulnerability management for this segment now demands the same rigor applied to the rest of the environment — with one critical nuance: on these devices, patching fast is not always patching right.

