Citrix NetScaler CVE-2026-88771/88772 patch checklist
Two actively exploited Citrix NetScaler flaws can allow unauthenticated remote code execution. Here is what UAE businesses should check, patch and preserve before changing anything.
Two actively exploited Citrix NetScaler flaws can allow unauthenticated remote code execution. Here is what UAE businesses should check, patch and preserve before changing anything.

If your UAE business runs a customer-managed Citrix NetScaler ADC or NetScaler Gateway, identify the appliance, record its version, check for compromise and move to Citrix’s fixed builds. CVE-2026-88771 and CVE-2026-88772 are critical flaws, and CISA says both are being exploited globally. This is not a routine monthly patch.
Citrix says the affected supported builds are earlier than 14.1-73.37 or 13.1-64.23, with separate FIPS and NDcPP build guidance. The fixed builds are 14.1-73.37 and 13.1-64.23, alongside the corresponding FIPS releases. Citrix-managed cloud services are handled by Cloud Software Group, but customer-managed appliances remain the customer’s responsibility. Citrix’s security bulletin is the version check to use.
An internet-facing access gateway with an exploited RCE flaw is an incident-review problem as well as a patching problem.

CVE-2026-88771 is an improper input-validation vulnerability. Citrix and CISA describe it as capable of allowing an unauthenticated attacker to execute arbitrary commands remotely.
CVE-2026-88772 is a memory-corruption issue. It can lead to remote code execution or denial of service. CISA says both vulnerabilities can independently enable remote code execution, which matters because an attacker does not necessarily need to chain several weaknesses to gain a foothold.
Citrix says exploitation has been observed on unmitigated NetScaler deployments. CISA added both CVEs to its Known Exploited Vulnerabilities catalogue on September 27, 2026, and said partner intelligence confirmed active exploitation globally. The agency’s alert on the two NetScaler flaws also warns that updating an appliance can require downtime.
CISA’s federal remediation deadline is aimed at US civilian agencies. It is not a UAE business deadline. The useful message for an owner here is different: these flaws have moved from theoretical exposure to confirmed exploitation, so a NetScaler appliance should be treated as a high-priority internet-facing asset.
NetScaler is commonly placed at the edge of an organisation. It may provide access to internal applications, desktops or remote services. If it is compromised, the risk is not limited to the appliance. The attacker may be able to use it as a route towards accounts, internal systems or business data. That is why patching without checking the surrounding environment can leave an important question unanswered: was the device already accessed?
A UAE firm does not need to shut down every system because a US agency issued an alert. It does need to establish whether it owns, leases or inherits a vulnerable appliance through an IT supplier, hosting company or group business.
CISA specifically advises organisations to check for indicators of compromise before updating where possible. It also warns that an update may remove forensic visibility, so suspected compromise should be handled as an evidence-preservation exercise rather than a simple software upgrade.
If your company has no NetScaler appliance, there is no reason to buy new security tooling for this alert. Ask your IT provider to confirm that in writing, then keep the confirmation with your supplier and asset records.
If you do have one, the sensible sequence is version check, evidence check, patch, credential review and service validation. Do not let a patch window become an excuse to postpone the review. Conversely, do not ask a web developer or general business consultant to investigate a NetScaler compromise unless they have the right security capability.
Paknology has a commercial interest in [ERP and automation work]( /services/erp-automation) only where the incident creates a separate need to document or streamline business workflows. We are not a NetScaler incident-response provider. For this issue, your existing IT administrator or a specialist security firm may be the cheaper and simpler option; if you need help deciding which business systems are affected, you can talk to us.
Sources
Book a free consultation and get a clear roadmap — from company formation to a fully automated digital operation.