What should Citrix NetScaler ADC and Gateway administrators do before applying patches for the exploited zero-days?

CISA’s practical advice for Citrix NetScaler ADC and NetScaler Gateway administrators was not just “patch.” The agency urged users and administrators to review Citrix’s advisories and, where possible, look for signs of compromise before applying patches.
What admins should do first
Before patching, administrators should use Citrix’s advisories as the main technical reference and check for possible signs of compromise where they can.
That matters because CISA reported active global exploitation of the vulnerabilities based on reports and partner threat intelligence. The supplied context does not list indicators, logs to inspect, or product-specific patch steps, so those details should come from Citrix’s advisories and official CISA updates.
Which vulnerabilities are involved
CISA identified CVE-2026-88771 and CVE-2026-88772 as critical zero-day issues. CISA also added both to its Known Exploited Vulnerabilities Catalog.
The agency says each of those two vulnerabilities can separately allow remote code execution.
Keep the guidance current
Because this is an actively exploited security issue, check CISA and Citrix’s official materials before acting on technical steps, indicators, or patch sequencing.
Which Citrix NetScaler vulnerabilities were added to CISA’s Known Exploited Vulnerabilities Catalog?

CISA added two Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities Catalog: CVE-2026-88771 and CVE-2026-88772.
The CVEs added to the catalog
The two catalog additions identified in the supplied context are:
- CVE-2026-88771
- CVE-2026-88772
CISA described both as critical zero-day issues affecting Citrix NetScaler ADC and NetScaler Gateway products.
Why they matter
CISA says each vulnerability can separately allow remote code execution. The agency also reported active exploitation globally, based on reports and partner threat intelligence.
The broader Citrix disclosure highlighted eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway products, but the supplied context specifically names CVE-2026-88771 and CVE-2026-88772 as the critical zero-days added to the KEV Catalog.
What to check next
For remediation details, administrators should review Citrix’s advisories and the latest CISA alerts. The supplied context does not include patch commands, affected version ranges, or compromise indicators.
Sources / Learn more
Related reading
- Should you watch Netflix’s Dark before HBO’s It: Welcome to Derry season 2?
- How do I buy tickets for the 2027 Kentucky Derby and Kentucky Oaks?; What is included with reserved seating for the 2027 Kentucky Derby and Kentucky Oaks?; When are the 2027 Kentucky Derby and Kentucky Oaks scheduled?; How can I follow 2027 Kentucky Derby and Kentucky Oaks contenders before race day?
- What is the order of matches on Day 1 of the Laver Cup 2026 at The O2 on Friday, September 25?; What does Team Europe choosing to pick their lineup first on Saturday and second on Sunday mean for the rest of the weekend?; How is Team Europe’s push for revenge in 2026 shaping up compared to last year’s 15-9 loss to Team World in San Francisco?
- What time do the Friday Foursomes matches start at the Presidents Cup, and who is paired against whom?; What does the U.S. team’s 3-2 lead after Four-ball mean given how often the U.S. has led after Day 1 in past Presidents Cups?

Leave a Reply