On 27 September 2026, Citrix published a bulletin covering eight NetScaler ADC and NetScaler Gateway vulnerabilities. Two of them, CVE-2026-88771 and CVE-2026-88772, are critical and are being exploited in the wild. They affect an access boundary that is often internet-facing: the gateway publishing applications or remote access.
What the advisories confirm
CVE-2026-88771 enables unauthenticated remote code execution under the conditions described by Citrix. CVE-2026-88772 is another critical flaw that can lead to code execution or denial of service. CISA added both to its KEV catalog, while CERT-EU recommends patching and checking for compromise.
Severity scores are not enough to assess this situation: active exploitation and the gateway’s role make an accurate appliance inventory more urgent than waiting for a normal maintenance cycle.
The scope to review
List NetScaler ADC and Gateway appliances, versions, builds and network exposure. Include standby, test and provider-managed environments. Record virtual servers, authentication profiles, VPN access and published applications.
Do not assume an instance is out of scope because it is not used as a VPN: the Citrix matrix and the real configuration determine applicability. Review filtering rules and administrative paths as well.
Patch, then look for evidence
Apply the fixed builds listed by Citrix, with a verified backup and rollback plan. After updating, review access logs, account creation, configuration changes and unexpected processes. A patch does not prove that earlier exploitation did not occur.
If the appliance was directly reachable from the Internet, preserve useful evidence before rotation or cleanup. Have your security team or managed service provider assess the indicators.
Accounts and secrets to review
Inventory administrator accounts, certificates, API keys and service secrets used by published applications. Prepare a coordinated rotation if the investigation shows that configuration was read or changed. Review fallback accounts too: they can remain active after a migration.
The workflow should separate software remediation, compromise assessment and access re-establishment. Completing only one does not replace the other two.
How Soclyde fits
Soclyde does not patch NetScaler and cannot determine whether an appliance was compromised. It can help keep administrator and service access in a local-first encrypted vault, using distinct credentials for each purpose.
That organization supports rotation after the investigation without turning the vault into a detection tool or a substitute for Citrix remediation.
Key takeaway
Two NetScaler zero-days are being exploited and require urgent operational treatment. Inventory gateways, apply Citrix builds, search for evidence and review secrets. To prepare a rotation, see the secure password generator or contact Soclyde.



