Guide2026-10-024 min read

Citrix NetScaler CVE-2026-88771/88772 patch checklist

Two actively exploited Citrix NetScaler flaws can allow unauthenticated remote code execution. Here is what UAE businesses should check, patch and preserve before changing anything.

Citrix NetScaler CVE-2026-88771/88772 patch checklist

Citrix NetScaler fixed builds and patch steps

If your UAE business runs a customer-managed Citrix NetScaler ADC or NetScaler Gateway, identify the appliance, record its version, check for compromise and move to Citrix’s fixed builds. CVE-2026-88771 and CVE-2026-88772 are critical flaws, and CISA says both are being exploited globally. This is not a routine monthly patch.

Citrix says the affected supported builds are earlier than 14.1-73.37 or 13.1-64.23, with separate FIPS and NDcPP build guidance. The fixed builds are 14.1-73.37 and 13.1-64.23, alongside the corresponding FIPS releases. Citrix-managed cloud services are handled by Cloud Software Group, but customer-managed appliances remain the customer’s responsibility. Citrix’s security bulletin is the version check to use.

An internet-facing access gateway with an exploited RCE flaw is an incident-review problem as well as a patching problem.

A generic rack-mounted network appliance sits beside a sealed evidence tray and an open maintenance shield.
A generic rack-mounted network appliance sits beside a sealed evidence tray and an open maintenance shield.

What CVE-2026-88771 and CVE-2026-88772 do

CVE-2026-88771 is an improper input-validation vulnerability. Citrix and CISA describe it as capable of allowing an unauthenticated attacker to execute arbitrary commands remotely.

CVE-2026-88772 is a memory-corruption issue. It can lead to remote code execution or denial of service. CISA says both vulnerabilities can independently enable remote code execution, which matters because an attacker does not necessarily need to chain several weaknesses to gain a foothold.

Citrix says exploitation has been observed on unmitigated NetScaler deployments. CISA added both CVEs to its Known Exploited Vulnerabilities catalogue on September 27, 2026, and said partner intelligence confirmed active exploitation globally. The agency’s alert on the two NetScaler flaws also warns that updating an appliance can require downtime.

UAE business impact of exploited NetScaler flaws

CISA’s federal remediation deadline is aimed at US civilian agencies. It is not a UAE business deadline. The useful message for an owner here is different: these flaws have moved from theoretical exposure to confirmed exploitation, so a NetScaler appliance should be treated as a high-priority internet-facing asset.

NetScaler is commonly placed at the edge of an organisation. It may provide access to internal applications, desktops or remote services. If it is compromised, the risk is not limited to the appliance. The attacker may be able to use it as a route towards accounts, internal systems or business data. That is why patching without checking the surrounding environment can leave an important question unanswered: was the device already accessed?

A UAE firm does not need to shut down every system because a US agency issued an alert. It does need to establish whether it owns, leases or inherits a vulnerable appliance through an IT supplier, hosting company or group business.

UAE NetScaler patch and evidence checklist

CISA specifically advises organisations to check for indicators of compromise before updating where possible. It also warns that an update may remove forensic visibility, so suspected compromise should be handled as an evidence-preservation exercise rather than a simple software upgrade.

  • —Ask the IT administrator or managed-service provider for every NetScaler ADC and Gateway asset, its public address, software version and owner.
  • —Compare each version with Citrix’s affected and fixed-build table, including FIPS and NDcPP variants.
  • —Before patching, use Citrix’s available indicators of compromise and preserve relevant evidence if suspicious activity is found.
  • —Record active sessions, recent administrator activity, configuration changes and unusual outbound connections for the incident reviewer.
  • —Apply the vendor update through the approved change process, with a rollback plan and a named person responsible for service validation.
  • —After the update, review privileged credentials and sessions connected to the appliance, especially if the device was exposed and unpatched.

What UAE NetScaler owners should do next

If your company has no NetScaler appliance, there is no reason to buy new security tooling for this alert. Ask your IT provider to confirm that in writing, then keep the confirmation with your supplier and asset records.

If you do have one, the sensible sequence is version check, evidence check, patch, credential review and service validation. Do not let a patch window become an excuse to postpone the review. Conversely, do not ask a web developer or general business consultant to investigate a NetScaler compromise unless they have the right security capability.

Paknology has a commercial interest in [ERP and automation work]( /services/erp-automation) only where the incident creates a separate need to document or streamline business workflows. We are not a NetScaler incident-response provider. For this issue, your existing IT administrator or a specialist security firm may be the cheaper and simpler option; if you need help deciding which business systems are affected, you can talk to us.

Ready to launch, automate and scale?

Book a free consultation and get a clear roadmap — from company formation to a fully automated digital operation.