Skip to content

Field notes · IT security ·

When a patch is available but not yet deployed

On 27 September, Citrix released fixes for two critical flaws in NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772. Both had been exploited before fixes were available. For an organisation using NetScaler to provide access to its services, the release date is therefore only part of the story. The date the fix reaches each appliance also matters.

Three windows of exposure

Before disclosure, some attackers knew about and exploited the flaws while public information and fixes were unavailable. The start of that period is usually unknown.

Once fixes were released, organisations knew what to update. Until a change was planned and completed, appliances running older builds remained vulnerable. The length of this window depends in part on how an organisation handles urgent changes.

Technical information followed quickly: an analysis of CVE-2026-88771 appeared on 28 September and one of CVE-2026-88772 on 29 September. Comparing vulnerable and fixed builds helped explain the root causes. Other actors could therefore learn more about the flaws while some appliances were still awaiting updates.

The scope of the first flaw matters. CVE-2026-88771 affects all deployments on vulnerable versions, including default configurations. CVE-2026-88772 requires DTLS, which is enabled by default on VPN virtual servers.

[1] [4] [5]

What the sample showed

We examined an illustrative sample of 50 publicly discoverable deployments. They included appliances used by banks, hospitals and critical infrastructure operators. We used publicly available records from internet device search engines and checked the information against several independent sources. We did not connect directly to the IP addresses, test the vulnerabilities or attempt exploitation.

By 1 October, four days after the fixes were released, we had confirmed a fixed build on 17 of the 50 appliances, or 34%. The other 33 ran builds older than the fix and were therefore affected by at least CVE-2026-88771. This sample does not represent the whole market. It illustrates the gap between a fix becoming available and being deployed.

How to read the result

Four days is a short period in which to update an important access appliance. A change may require approval, a maintenance window, updating both members of an HA pair and testing service availability. A delay alone says nothing about the work of individual administrators.

The case does show the tension between a normal change cycle and a flaw already being exploited. Without a procedure for urgent security updates, the normal change process may determine how long it takes to deploy a fix.

An older build does not mean an appliance was compromised. A fixed build does not prove that no compromise occurred before the update. Citrix notes that updating addresses the vulnerabilities going forward but does not remove the effects of a prior compromise.

[3]

What follows

When an actively exploited flaw affects an internet-facing appliance, an organisation needs an accurate inventory of its appliances and builds, including standby and test instances. It also needs a way to deploy critical updates faster than routine maintenance allows.

The period before the fix needs attention too. CISA advises checking for signs of compromise before updating where possible and preserving forensic evidence first if compromise is suspected. An update may reduce the ability to establish what happened on the appliance.

The availability of a fix starts the response. Deployment determines the length of exposure; preserved evidence and investigation help establish what happened before it.

[2]

Sources

  1. Citrix NetScaler security bulletin CTX697096
  2. CISA alert, 27 September 2026
  3. Citrix guidance on indicators of compromise
  4. watchTowr analysis of CVE-2026-88771
  5. watchTowr analysis of CVE-2026-88772

← Back to IT services