Citrix NetScaler Flaws Under Active Attack: Patch Now

What happened
Over the weekend, the U.S. Cybersecurity and Infrastructure Security Agency added two critical vulnerabilities in Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities (KEV) catalog, following reports that attackers are already using them in the wild. One of the two, CVE-2026-88771, carries a CVSS score of 9.5 and stems from improper input validation that an unauthenticated attacker could abuse, according to reporting picked up via feeds.feedburner.com.
A KEV listing is not a theoretical advisory. It is CISA saying, in effect, "this is being used against real organizations right now." Federal civilian agencies are bound to remediation deadlines under BOD 22-01; everyone else should treat the listing as the practical equivalent. Because the second CVE and the full list of affected build numbers were not spelled out in the summary we saw, do not take our word for version coverage: pull the current KEV entry and the vendor's own security bulletin and confirm your exact firmware build against them before you declare yourself safe.

Why this matters for Pittsburgh small and mid-sized businesses
NetScaler ADC and Gateway appliances sit at the front door. They terminate remote access, publish internal apps, load-balance, and broker authentication. That means a successful pre-authentication exploit is not a nuisance on a workstation somewhere; it is a foothold on the device that sees your traffic and holds your session tokens. Historically, attacks against this class of edge appliance have been about session hijacking and persistence that survives a reboot, so patching alone may not be the end of the story.
If you are a 10-to-200-person firm in the region, you may be more exposed than you think. Plenty of Pittsburgh CPA practices, law firms, specialty medical groups, and manufacturers inherited a NetScaler or a Citrix-published desktop environment from a line-of-business vendor, a practice-management host, or an ERP implementation years ago. It gets renewed quietly, it is rarely in anyone's patch cycle, and nobody on staff owns it. Ask two questions today: do we have one, and who is responsible for its firmware?
The compliance math is unforgiving here too. For a healthcare client, an unpatched internet-facing appliance is a direct hit on the HIPAA Security Rule's risk-management and evaluation requirements, and a breach through it is very hard to argue away as low-probability-of-compromise. For financial services and accounting, the FTC Safeguards Rule expects a documented program that includes patching and monitoring of systems handling customer information, and tax practices carry their own IRS written-security-plan obligations. Defense suppliers pursuing or maintaining CMMC Level 2 are evaluated against NIST SP 800-171 controls for flaw remediation and boundary protection, and a KEV-listed CVE left open is exactly the kind of finding that ends an assessment badly. Any SOC 2 examination will ask for evidence you acted on this within a defined window, not just that you eventually did.
There is also a supply-chain dimension that our manufacturing and defense clients feel first. If your remote-access gateway is compromised, the phone call you dread is not from your own users, it is from a prime contractor or a customer asking why traffic from your network looks wrong. Remediation timelines get set by other people at that point.
What to do about it this week
- Inventory every edge appliance, not just Citrix. Confirm in writing whether your environment includes NetScaler ADC or Gateway, and where. Include devices managed by software vendors or hosting partners, and include anything sitting in a co-lo you have not visited in a while. Same pass should catch VPN concentrators and firewalls with remote-access portals.
- Get the exact firmware build and compare it to the vendor bulletin. Verify the specific fixed release for your platform and edition. If you cannot patch the same day, document a compensating control, such as restricting management access and geo- or IP-fencing the gateway, and set a firm date.
- Assume session compromise until proven otherwise. After patching, rotate credentials and revoke or invalidate active sessions on the appliance, then rotate any secrets stored on or reachable from it. For pre-auth bugs of this class, patching without invalidating sessions is a common and expensive mistake.
- Hunt for evidence before the logs roll off. Pull authentication logs, look for logins from unfamiliar geographies or impossible travel, check for unexpected admin accounts or configuration changes, and preserve a copy off the device. Your EDR/MDR telemetry from the servers behind the gateway matters as much as the appliance logs.
- Enforce phishing-resistant MFA on everything the gateway fronts. If a stolen session gets an attacker into a published app, the next hop is usually your identity plane. Review conditional access policies and legacy authentication in Microsoft 365 while you are in there.
- Decide whether the appliance still earns its place. Many of these deployments exist to publish one application. Modern identity-aware access or a cloud-hosted equivalent often removes an entire class of internet-facing risk. That is a technology roadmap conversation, and a good one to have in Q4 budgeting.
- Write the whole thing down. Date discovered, date patched, evidence reviewed, decisions made. Our compliance clients will need this artifact for their next HIPAA risk analysis, SOC 2 window, or CMMC assessment, and it is far easier to capture now than to reconstruct in six months.
How we help
Our managed IT team already runs patch management and edge-device monitoring for clients across the region, and when a KEV entry like this lands we work the affected estate as an incident, not a ticket queue item: inventory, verify build, patch, rotate, hunt, document. If nobody has confirmed your remote-access appliances are on a fixed release, that is a one-conversation problem to close out.
Call us at 724.888.7007 or reach us through the contact form, and we will get a NetScaler exposure check on your calendar this week.
Related reading

Unpatched Citrix NetScaler Zero-Days: What To Do Now
Two unpatched Citrix NetScaler zero-days are under active exploitation. What Pittsburgh SMBs, CPA firms, clinics, and defense contractors should do now.

ClickFix Fake CAPTCHAs Are Tricking Office Users Into Self-Infecting
A new CTM360 report maps 17,000 ClickFix URLs. Here is what Pittsburgh SMBs in legal, CPA, healthcare and defense work should verify and train on now.

Chrome and Windows Zero-Day Chain: What Pittsburgh SMBs Should Do Now
A Chinese threat actor chained Chrome and Windows zero-days via fake websites. Here is what Pittsburgh small and mid-sized businesses should verify and patch now.