How can administrators check whether Citrix NetScaler ADC or NetScaler Gateway is exposed to CVE-2026-88771 or CVE-2026-88772?

If you administer Citrix NetScaler ADC or Citrix NetScaler Gateway, the first question is simple: could your environment be affected by either of the two critical zero-days CISA flagged?
Start with the official Citrix advisories
CISA’s alert says administrators should review Citrix’s advisories, assess exposure, prioritize mitigation, and check for compromise before patching when possible.
The confirmed exposure check from the available notice is therefore not a guesswork checklist. It is:
- Identify whether your organization uses Citrix NetScaler ADC or Citrix NetScaler Gateway.
- Review Citrix’s advisories for the eight vulnerabilities CISA relayed.
- Pay special attention to CVE-2026-88771 and CVE-2026-88772, because CISA identifies both as critical zero-days that can allow remote code execution.
- Compare your deployed NetScaler products and configurations against the affected information in Citrix’s advisories.
- Prioritize mitigation if either product is exposed.
The context provided here does not include affected version numbers, fixed builds, configuration conditions, or specific commands to run. Those details need to come from Citrix’s own advisory materials.
Why the check is urgent
CISA says reports and partner intelligence indicate active global exploitation by threat actors. It also added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities Catalog.
That means this is not just a routine patch review. If NetScaler ADC or NetScaler Gateway is in your environment, exposure assessment should move ahead of lower-priority maintenance work.
What not to assume
Do not assume you are safe only because a system has not shown obvious symptoms. CISA specifically urges users and administrators to check for compromise before patching when possible.
Also avoid relying on unofficial summaries for product-specific details. This information can change as Citrix and CISA update their notices, so use the official advisory as the current source of truth.
What should Citrix NetScaler administrators do before patching if compromise is suspected?

If compromise is suspected on Citrix NetScaler ADC or Citrix NetScaler Gateway, CISA’s advice is to check for compromise before patching when possible.
The immediate order of operations
CISA’s alert does not provide a full incident-response playbook in the provided context, but it does give a clear priority sequence:
- Review Citrix’s advisories.
- Assess whether the NetScaler environment is exposed.
- Prioritize mitigation.
- Check for compromise before patching when possible.
That last point matters because patching can reduce future exposure, but administrators may still need to understand whether threat actors already exploited the device.
What the compromise check should be based on
The available context confirms that CVE-2026-88771 and CVE-2026-88772 are critical zero-days that can each allow remote code execution. It also says active global exploitation has been reported through CISA’s reports and partner intelligence.
The context does not include indicators of compromise, log paths, forensic commands, or detection rules. Administrators should not invent those steps from partial information. Use Citrix’s advisories and CISA’s notice to find the latest recommended checks.
Why patching alone may not answer the question
A patch or mitigation addresses the vulnerable condition going forward. It does not, by itself, confirm whether the system was already accessed.
That is why CISA’s wording matters: check for compromise before patching when possible. If your team has reason to suspect exploitation, treat the review as both a mitigation task and a compromise-assessment task.
Because this situation is active, recheck the official CISA and Citrix materials before acting on any saved copy of the instructions.
What changed after CISA added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities Catalog?

CISA’s addition of CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities Catalog changed the urgency around the Citrix NetScaler issue.
The main change: confirmed exploitation priority
The two CVEs were not only described as critical. CISA also added them to the KEV Catalog, which is reserved for known exploited vulnerabilities.
In practical terms, administrators should treat CVE-2026-88771 and CVE-2026-88772 as active-risk items, not theoretical vulnerabilities waiting for later review.
What CISA says administrators should do now
CISA urges users and administrators to:
- review Citrix’s advisories
- assess exposure
- prioritize mitigation
- check for compromise before patching when possible
That sequence is the clearest operational takeaway from the available context. The alert also notes active global exploitation based on reports and partner intelligence.
What the KEV listing does not tell you by itself
The available context does not provide affected versions, fixed releases, exploit details, or product-specific checking commands. The KEV addition increases urgency, but administrators still need Citrix’s advisory details to determine exactly what applies to their own NetScaler ADC or NetScaler Gateway deployment.
For the latest status, check the official CISA alert and Citrix’s advisory materials rather than relying on older summaries.
Sources / Learn more
Related reading
- What should Citrix NetScaler ADC and Gateway administrators do before applying patches for the exploited zero-days?; Which Citrix NetScaler vulnerabilities were added to CISA’s Known Exploited Vulnerabilities Catalog?
- What should NetScaler ADC and Gateway administrators do first after CISA added CVE-2026-88771 and CVE-2026-88772 to the KEV Catalog?; Which Citrix products are affected by CVE-2026-88771 and CVE-2026-88772?; How are CVE-2026-88771 and CVE-2026-88772 different?; When did CISA add the two Citrix NetScaler vulnerabilities to the Known Exploited Vulnerabilities Catalog?

Leave a Reply