After the patch: verifying remediation for CVE-2026-88772 on NetScaler ADC and Gateway
A completed maintenance window and a remediated appliance are not the same claim. The Citrix NetScaler
advisory CTX697096 of 27 September 2026, with CVE-2026-88771 and CVE-2026-88772 confirmed as exploited,
sets a higher bar for what counts as done.
Confirm the build, not the activity
The first verification is the version string. Fixed builds are 14.1-73.37 and later for NetScaler ADC and
Gateway 14.1, 13.1-64.23 and later for 13.1, 14.1-73.37 FIPS and later for ADC FIPS, and 13.1-37.279 and
later for ADC FIPS and NDcPP. A change ticket marked complete with an older string still leaves the
appliance in the affected range, which is why the check belongs against the running appliance rather than
against the ticket.
Confirm the roles that carried the prerequisites
Two of the flaws in the bundle depend on how the device is used. CVE-2026-88772 needs DTLS, which Citrix
describes as enabled by default on a VPN virtual server. CVE-2026-88773 needs HTTP enabled. CVE-2026-88775
applies to Gateway roles including SSL VPN, ICA Proxy, CVPN and RDP Proxy, or to an AAA virtual server.
CVE-2026-88776 requires an Oracle-type load-balancing virtual server, and CVE-2026-88777 requires a
load-balancing, content-switching or CGNAT LSN/NAT64 configuration with a non-HTTP Layer 7 protocol.
Re-checking these after an upgrade also catches defaults that were inherited at object creation and
never revisited.
Confirm the evidence was captured before the change
Because exploitation preceded the fixes, NCSC-NL advises preserving relevant logging and a memory dump
before installing the update, reviewing them afterwards, and checking the indicators of compromise
Citrix published through the NetScaler console. A remediation record that shows only the firmware date
has skipped the part of the advisory that concerns what already happened. Logs, build string, running
configuration and any crash material should be attached to the change, not just referenced.
Confirm the estate, not the sample
A patch wave usually covers the appliances someone remembered. Failover and standby units must be
checked independently, because a switchover during an incident will move traffic onto whatever the
standby is running. Hybrid Secure Private Access deployments that use NetScaler instances belong in the
same verification pass.
Confirm the residual questions
Even a clean verification leaves two open items worth recording: whether the exposure period produced any
indicator that has not yet been reviewed, and whether Citrix-managed components are in scope. The latter
are updated by Cloud Software Group under a separate arrangement, while the advisory covers
customer-managed appliances. Writing those down keeps the case closable rather than merely quiet.
Exposure context for the record
A ZoomEye query for app="Citrix NetScaler" matched 239,201 assets at query time, and the CVE filter
vul.cve="CVE-2026-88772" matched none. The second number describes index timing for a recent disclosure;
the first describes visible product instances, not confirmed victims. Neither substitutes for the
per-appliance verification above.
Exposure context
A ZoomEye query for app="Citrix NetScaler" matched 239,201 internet-facing assets at query time. The
CVE-indexed filter vul.cve="CVE-2026-88772" returned zero. For a disclosure this fresh, an index miss is
expected and should not be read as an exposure estimate; nor does a fingerprint match prove a device is
vulnerable, only that it presents as NetScaler ADC or Gateway.
Remediation and mitigations
The fixed builds named by Citrix and repeated by NCSC-NL and CERT-FR are 14.1-73.37 and later on the 14.1
branch, 13.1-64.23 and later on 13.1, 14.1-73.37 FIPS and later for ADC FIPS, and 13.1-37.279 and later
for ADC FIPS and NDcPP. Both CVE-2026-88771 and CVE-2026-88772 were exploited before these builds
existed, so NCSC-NL advises securing relevant logs and a memory dump before the update, reviewing them
afterwards, and checking the indicators of compromise Citrix published through the NetScaler console. The
update prevents further abuse; it does not resolve whether abuse already occurred.
References
- NCSC-NL advisory NCSC-2026-0394: https://advisories.ncsc.nl/2026/ncsc-2026-0394.html
- CERT-FR alert CERTFR-2026-ALE-011: https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-011/
- CERT-FR advisory CERTFR-2026-AVI-1235: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1235/
- Citrix bulletin CTX697096: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
Top comments (0)