Back to Blog

Critical Citrix NetScaler vulnerabilities – patch your gateway now

Critical Citrix NetScaler vulnerabilities – patch your gateway now
September 30, 2026|David Velarde RoblesDavid Velarde Robles

Why critical Citrix NetScaler vulnerabilities matter now

Two critical zero‑day flaws have been discovered in the Citrix NetScaler Application Delivery Controller (ADC) and Gateway – the devices many small businesses use to let employees, customers and partners connect to internal applications over the internet.

What makes this different from a typical security advisory is that threat actors are already exploiting the flaws, and government cyber agencies in the UK, the Netherlands and the US have added them to their “known exploited vulnerabilities” lists. If your business relies on the gateway appliance, an attacker could already be trying to run code on your server or bring the service down, potentially causing data loss, downtime, or a costly breach.

The two critical CVEs explained

CVE What it does Why it matters
CVE‑2026‑88771 Improper input validation lets an unauthenticated attacker send specially crafted data that executes arbitrary commands on the device. An attacker can take full control of the gateway, read or modify traffic, and move laterally into other systems.
CVE‑2026‑88772 A memory‑overflow condition that can cause a denial‑of‑service (DoS) or remote code execution (RCE – an attacker runs their own code on the device, like installing a backdoor). The device can be knocked offline, or the same kind of full control can be achieved as with the first flaw.

Both vulnerabilities can be triggered without any credentials – the attacker only needs the device to be reachable from the internet, which is exactly how NetScaler is normally exposed.

Which versions are at risk

The flaws affect the following releases:

  • NetScaler ADC and Gateway 13.1 and 14.1 before 13.1‑64.23 and 14.1‑73.37
  • NetScaler ADC FIPS before 14.1‑73.37 FIPS
  • NetScaler ADC FIPS and NDcPP before 13.1‑37.279

Citrix released patches on 27 September 2026. If you are running any version older than the numbers above, you are vulnerable.

Immediate checklist – what to do today

  1. Identify the version – Log into the NetScaler management console or run show version from the CLI. Write down the exact build number.
  2. Compare with the safe versions – If your build is older than the numbers listed, you must patch.
  3. Download the official patch – Go to the Citrix security bulletin and download the appropriate update for your product line.
  4. Schedule a maintenance window – Applying the patch will restart the appliance and may temporarily cut off remote access. Plan for a short outage, inform users, and have a rollback plan in case the update fails.
  5. Apply the patch – Follow Citrix’s step‑by‑step guide. The process is usually a single command or a few clicks in the UI.
  6. Test connectivity – After the reboot, verify that internal applications are still reachable and that external users can log in.
  7. Monitor logs – Look for any unusual login attempts or error messages in the system logs for the next 24‑48 hours.
  8. Isolate if you cannot patch immediately – Place the device in a segmented network zone, block inbound traffic from the internet, and use a temporary VPN or reverse‑proxy solution for remote access. This reduces the attack surface while you arrange the update.

How IT Move NL can help

Dealing with a critical vulnerability while keeping your business running is stressful. Our Security & Protection service includes:

  • Patch management – We monitor vendor advisories, test updates in a sandbox, and apply them during a planned window, minimizing downtime.
  • Vulnerability scanning – Regular scans identify outdated components before they become a problem.
  • 24/7 monitoring – Our team watches logs and network traffic for signs of exploitation, so you don’t have to.

Combined with our Maintenance & Support package, you get a single point of contact for all your critical infrastructure – from gateways to web servers and cloud services. Let us take the technical burden off your shoulders so you can focus on running your business.

Ready to secure your gateway? Get in touch today for a free health check of your Citrix NetScaler (or any other gateway appliance). We’ll verify the version, apply the patch, and set up monitoring – all with minimal disruption to your operations.

Frequently asked questions about Citrix NetScaler security

Q: I don’t know if we use Citrix NetScaler. How can I find out?
A: Check with the person who set up your remote access or look at the device’s web interface. The branding usually says “Citrix NetScaler” on the login screen. If you see a separate “gateway” appliance handling VPN or web‑app traffic, it’s likely the one in question.

Q: Will patching cause my employees to lose access to critical apps?
A: The patch requires a brief reboot of the gateway, which will interrupt remote connections for a few minutes. Schedule the update during off‑peak hours and inform users in advance to avoid surprise downtime.

Q: My business can’t afford a long outage. Is isolating the device enough?
A: Isolation reduces the risk dramatically but does not eliminate it. It’s a stop‑gap measure while you arrange the patch. If you need a temporary remote‑access solution, we can set up a secure VPN that bypasses the vulnerable gateway until the update is complete.


Sources:

David Velarde Robles
David Velarde Robles

He/Him · AWS Certified Solutions Architect | Cloud Engineer @ Essent

Cloud Engineer at Essent B.V. with 10+ years of experience in the tech industry. AWS Certified, passionate about serverless architectures, Infrastructure as Code, and DevOps. Proficient in TypeScript, Python, and Terraform. Based in Amersfoort, Netherlands.

>

STAY IN THE LOOP

// Cloud, AI & DevOps insights — straight to your inbox.

>

No spam. Unsubscribe anytime.

Share this article:

Need help with your cloud infrastructure?

Our team of experts is ready to help you navigate the complexities of modern cloud architecture.

Get in Touch