
The Trust is Gone: Rethinking Citrix NetScaler
If you have worked with Citrix for any length of time, you’ve probably had at least one difficult conversation about NetScaler. Maybe it was a late-night maintenance window. Maybe it was an emergency patch. Maybe it was a frantic meeting after another critical vulnerability announcement.
The security bulletin Citrix issued on September 27, 2026 covering CVE-2026-88771 through CVE-2026-88778 feels uncomfortably familiar. Among the eight vulnerabilities disclosed are two critical remote code execution flaws – CVE-2026-88771 and CVE-2026-88772 – both rated 9.5 CVSS and both confirmed by Citrix as having been exploited in the wild. One affects default NetScaler deployments and can allow unauthenticated command execution. The other can lead to remote code execution when DTLS is enabled, which is the default configuration for many Gateways.
During the three-year period from October 4, 2023 to October 4, 2026 there have been:
- 13 distinct NetScaler security bulletins
- 34 individual CVEs
- At least six bulletins involving confirmed exploitation, including the bulletin described above which as of this writing may affect 42,000 instances
And that raises an uncomfortable question – How can you justify continuing to run NetScalers in your environment when the trust is gone?
“This Time Will Be Different”
Anyone who has been stuck with a persistent trust problem knows the cycle:
- Something bad happens
- Remediation is applied
- Conditions improve temporarily
- Then the pattern repeats
For many organizations, that cycle feels eerily similar to NetScaler ownership:
- A critical vulnerability is announced
- Emergency change windows are scheduled
- Executives ask if the environment is exposed
- Administrators spend nights or weekends patching appliances
- Security teams scramble to determine whether a compromise occurred before remediation
- Everyone exhales…
- Then, months later, the cycle begins again
The problem is no longer a single CVE. The problem is the pattern.
Unfortunately, this time customers barely had a chance to exhale. Soon after applying the update to address CVE-2026-88771 through 88778, many in the online community reported that their NetScalers started spontaneously rebooting. On October 4, 2026, only a week after customers scrambled to address the previous vulnerabilities and determine whether they had been compromised, Citrix issued a bulletin for CVE-2026-88779 describing a memory overflow vulnerability leading to denial of service and causing the reported reboots, leaving customers to scramble yet again to patch devices to ensure service to their users was not interrupted.
The Cost Isn’t Just Patching
When defenders discuss NetScaler vulnerabilities, focus often lands on patching:
- Upgrade the firmware
- Move on
But the actual cost is much larger. Every major NetScaler security event creates ripple effects:
- Emergency maintenance windows
- Business disruption risk
- Increased security monitoring
- Incident response investigations
- Executive reporting
- Compliance concerns
- Customer communications
- Lost productivity
The technical fix might take a few hours, but the organizational distraction and disruption can last for much longer.
With the latest vulnerabilities, organizations are being told not only to patch but also to determine whether exploitation may have occurred before remediation has been reported. That is a very different conversation from simply applying an update. When active exploitation is confirmed, every unpatched appliance effectively becomes a potential breach investigation.
The Internet-Facing Tax
The challenge is amplified because NetScaler frequently occupies one of the most dangerous positions in the enterprise – Direct exposure to the Internet.
Internal servers can often rely on layered defenses, but NetScalers frequently serve as:
- VPN gateways
- ICA Proxies
- External application publishing platforms
- Authentication endpoints
That means attackers are constantly looking at them. Every vulnerability isn’t simply another bug. It is another vulnerability on a device specifically designed to accept connections from unknown parties across the Internet. Organizations may spend enormous effort hardening backend workloads while simultaneously placing a highly privileged appliance in front of everything that matters.
The Security Team’s Perspective
Ask a security team how they feel about NetScaler, and you’ll often get a knowing smile. Not because NetScaler isn’t powerful, and not because it lacks functionality, but because they have been through this so many times before. Many security professionals view internet-facing infrastructure through a simple lens – How frequently does this product require emergency action?
Unfortunately, NetScaler has generated enough high-profile security events over the years that many organizations now factor in recurring emergency response effort into the total cost of ownership. A load balancer or access gateway should ideally be something nobody talks about, but NetScaler often becomes something everybody talks about.
“But We Still Need It”
Perhaps, but that assumption deserves a fresh look. The technology landscape has evolved significantly. Organizations today have options that did not exist a decade ago including:
Application Delivery and External Access
- Azure Application Gateway
- Azure Front Door
- Entra Private Access
- Cloud-native load balancing services
- ZTNA and SaaS-delivered application access solutions
Desktop and Application Delivery
- Azure Virtual Desktop
- Windows 365 Cloud PCs
Management Platforms
- Citrix DaaS configurations that do not require NetScaler
- Nerdio Manager for MSP
- Nerdio Manager for Enterprise
Final Thoughts
NetScaler remains a powerful product. Many organizations successfully operate it at scale, and many deployments continue to meet important business requirements. But power and necessity are not the same thing as trust. The latest vulnerabilities are significant because they include critical remote code execution flaws that Citrix has confirmed were exploited in the wild. support.citrix.com, watchtowr.com, tenable.com
For organizations still relying on NetScaler, if a compromise is suspected the steps to take are clear:
- Preserve evidence
- Isolate the device
- Revoke credentials and access
- Investigate connected systems
- Rebuild and restore the device
- Rotate restored secrets
- Harden the device
Once the immediate remediation efforts are complete, leadership should ask a broader question: Is NetScaler still the right strategic fit, or are we accepting recurring risk because change appears more disruptive than the status quo? Security incidents, emergency patching, and heightened operational overhead all contribute to the true cost of ownership. The question is no longer whether another critical vulnerability will emerge, but whether the business continues to receive enough value to justify the ongoing investment required to manage that risk.
Stay Connected
Looking for more ways to interact with Kraft Kennedy?
Check out our upcoming events!