Who is affected
Citrix NetScaler ADC and NetScaler Gateway are vulnerable to unauthenticated command execution due to improper input validation. The record does not specify which versions are affected, whether on-premises or cloud deployments are at greater risk, or the nature of the input vector. You should treat any NetScaler ADC or Gateway in your environment as potentially vulnerable unless you have confirmed a patch or vendor mitigation is in place.
How to check whether this touches you
- Search your asset inventory for any Citrix NetScaler ADC or NetScaler Gateway appliances, including those managed by third parties or deployed as cloud services.
- Determine whether each appliance is reachable from untrusted networks (the internet, partner networks, or compromised internal segments); unauthenticated exploitation means network access alone may be sufficient.
- Check the running software version on each appliance via the management console or CLI; version alone is not proof of patching, as vendors sometimes backport fixes, but it is your first signal.
- Review recent access logs to the management interface and any exposed service ports to establish a baseline for later forensic review.
What to do
- Contact Citrix support immediately to obtain the vendor's recommended mitigation or patch for your specific NetScaler version and deployment model.
- If patching is not immediately possible, apply network-level controls: restrict access to the NetScaler management interface and any exposed service ports to trusted networks only, and consider placing the appliance behind a firewall rule that rate-limits or blocks suspicious input patterns.
- Enable comprehensive logging of all requests to the NetScaler (management and data plane) and store logs off-device; configure alerts for any error conditions or input validation failures.
- If the appliance is internet-facing and a patch is not available within your remediation window, escalate to your security leadership for a decision on temporary service shutdown or product discontinuation per BOD 26-04 guidance.
If you find you were exposed
Exploitation of unauthenticated command execution vulnerabilities typically occurs before public disclosure, so you should assume that any appliance exposed to untrusted networks for more than a few days may have been compromised. Review all available logs from the date of the record's publication (27 September 2026) backwards to the last confirmed patch or baseline configuration change, looking for unusual command execution, new user accounts, or exfiltration of configuration or credential data. Log retention is often the limiting factor; if your logs do not extend back far enough, document that gap and treat the appliance as potentially compromised until further investigation is complete.