Who is affected
Citrix NetScaler ADC and NetScaler Gateway deployments are vulnerable to a memory buffer bounds issue that permits remote code execution or denial of service. The record does not specify which versions of NetScaler are affected, nor does it detail whether the vulnerability requires authentication or network proximity to exploit.
How to check whether this touches you
- Inventory your Citrix products: confirm whether you operate NetScaler ADC, NetScaler Gateway, or both, and in what deployment mode (on-premises, cloud-hosted, or hybrid).
- Establish network reachability: determine whether your NetScaler instances are accessible from the internet or from untrusted internal networks, or whether they are air-gapped and accessible only to defined administrators.
- Identify running versions: extract the firmware version from each appliance (visible in the management console or via SSH), noting that version numbers alone do not confirm patch status—Citrix may backport fixes into maintenance releases.
- Check vendor communications: review Citrix security bulletins and advisories for specific affected version ranges and patched builds.
What to do
- Obtain the latest Citrix security advisory for CVE-2026-88772 and confirm which NetScaler versions require action and which patches are available.
- If your instances are internet-facing or reachable from untrusted networks and you cannot patch immediately, restrict network access to the NetScaler management and data planes using firewall rules, network segmentation, or access control lists until a patch is deployed.
- Prioritise patching in accordance with CISA BOD 26-04 guidance: apply patches to internet-exposed instances first, then to internal-only appliances according to your risk assessment.
- If no patch is available from Citrix and mitigations are insufficient, evaluate whether discontinuation of the product or migration to an alternative solution is necessary under BOD 26-04 compliance requirements.
- Enable logging of all connections and administrative actions on affected NetScaler instances, and retain logs for forensic analysis.
- Escalate to your security team and incident response plan if you discover evidence of exploitation or unauthorised access.
If you find you were exposed
Exploitation of memory buffer vulnerabilities typically occurs before public disclosure, so assume any appliance with internet exposure or access from potentially compromised networks may have been targeted. Examine NetScaler audit logs and syslog records for suspicious administrative sessions, configuration changes, or unexpected process execution dating back several months before the CISA advisory date. Log retention constraints often limit retrospective visibility; prioritise preservation of any logs that predate the advisory by at least 90 days.