On September 27, the Cybersecurity and Infrastructure Security Agency (CISA) added two Citrix NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, to its Known Exploited Vulnerabilities Catalog. NetScaler ADC and NetScaler Gateway are appliances many organizations use to give staff remote access to internal applications. CISA described both flaws as "critical, zero-day vulnerabilities that can independently enable remote code execution." By October 9, the agency had revised its alert to cover ten related vulnerabilities.

Most coverage of a flaw like this stops at "patch now." CISA's alert asks for something more, and it is the step small organizations most often skip: find out whether an attacker got in before the patch, and treat that question as a separate job from the update itself.

The attackers were early

Palo Alto Networks' Unit 42 research team traced the earliest activity it found to August 21, 2026, when hosts began sending requests consistent with identifying which NetScaler version a device was running. Citrix published its security bulletin on September 27. In the weeks between, Unit 42 observed attackers delivering web shells, small hidden programs that give an intruder a way back in, to establish initial access and persistence inside organizations.

The exposure was wide. Unit 42 counted 50,277 exposed instances that could potentially be vulnerable as of September 27. Help Net Security reported on September 29 that security researcher Kevin Beaumont found fewer than 10 percent of exposed hosts patched, and that he was tracking over 100 victim organizations where "each one has a unique webshell which can't be scanned for remotely unless you're the attacker."

That timeline is the lesson. A device that was exploited in early September and patched in October is a patched device that may still have an intruder on it. Unit 42 put it in one line: "Updating and patching will not remove access for attackers that have already established persistence."

What CISA asks organizations to do

CISA was candid that the update itself is not simple: "Because updating Citrix NetScaler deployments can be complex and may require downtime, CISA is issuing this Alert to help organizations assess exposure, prioritize mitigation actions, and account for these vulnerabilities in their risk-management activities."

Its recommendations go further than the update. "CISA recommends organizations forward their NetScaler logs to a centralized security information and event management (SIEM) or log retention system, as local logs may rotate quickly and overwrite forensic artifacts." It adds: "Organizations that suspect compromise should preserve forensic evidence before applying updates, as updates may reduce forensic visibility." Where compromise is suspected, the alert calls for restoring a known good backup that pre-dates the compromise and rotating every restored secret, including local account passwords, key-encryption keys, and SSL certificates.

Even the vendor's own tooling has limits. Help Net Security reported that Citrix acknowledged its detection script "might fail to identify actual compromises," because attackers change their methods and infrastructure. A clean scan result is reassurance, not proof.

The federal standard points the same way

In June 2026, CISA issued Binding Operational Directive 26-04, Prioritizing Security Updates Based on Risk. It binds federal civilian agencies, and unless a contract says otherwise it does not apply to contractors. Its logic is still a useful model for any organization. For the highest-risk cases, the directive pairs the fix with a check: the agency "must complete remediation or mitigation action within the timeline (three days) and carry out a forensic triage of the asset to assess whether the system is compromised."

The directive also names a mitigation that small offices tend to overlook. When a device cannot be fixed quickly, removing it from the internet is a valid mitigation. In its October 4 catalog update, CISA extended the reasoning beyond government: "While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities." FCEB stands for the Federal Civilian Executive Branch, and KEV is the Known Exploited Vulnerabilities Catalog.

Why this matters if you do not run Citrix

Not every small business runs NetScaler. Most run something that plays the same role: a firewall with a built-in VPN, a remote desktop gateway, a remote-access portal, or a file-sharing appliance. These devices sit at the edge of the network, answer anyone on the internet, and hold the credentials that open everything behind them. When one is exploited before a fix exists, the patch ends the vulnerability without ending the intrusion. From there, an attacker can move to the systems behind the device, which is why a flat office network turns one compromised device into a compromised office, and why a password reset alone may not end an intrusion.

For defense subcontractors, NIST SP 800-171 already asks for both halves of this work: correcting system flaws in a timely manner, and keeping audit logs that support investigation of unauthorized activity. For medical and dental practices, the HIPAA Security Rule requires audit controls and security incident procedures. A forensic check before patching is where those requirements meet in practice.

A routine for every internet-facing device

A patch ends the vulnerability. Whether it also ends the incident depends on what happened before it was installed, and the only organizations that can answer that question are the ones that kept the logs and looked.

Sources

Know what is on the edge of your network

Adams Cloud & Cybersecurity helps small businesses inventory their internet-facing devices, forward the logs that matter, and check for compromise when a critical vulnerability lands.

Book a free consultation