The Citrix NetScaler zero-days are two critical remote code execution flaws, CVE-2026-88771 and CVE-2026-88772, that attackers exploited in NetScaler ADC and NetScaler Gateway before a patch existed. Citrix disclosed eight vulnerabilities on September 27, 2026, one day after security firm watchTowr reported active exploitation. Both critical bugs carry a CVSS score of 9.5, and CISA added them to its Known Exploited Vulnerabilities catalog the same day.
NetScaler ADC is an application delivery controller and load balancer; NetScaler Gateway provides VPN, remote access and authentication for employees and partners. That makes these appliances some of the most privileged devices in an enterprise network: they sit on the internet edge, terminate encrypted sessions and often hold credentials and session data for thousands of users.
The practical meaning is stark. An unauthenticated attacker who reaches a vulnerable appliance can run arbitrary commands on it. When the device that guards your front door is the vulnerable component, every other control behind it is exposed. For IT managers and CIOs, this is the clearest recent example of why edge appliances deserve the same attention as servers and endpoints, and why a 24/7 cybersecurity service that monitors and responds matters as much as the patch itself.
Why are edge appliances such attractive targets? Because they combine maximum exposure with minimum visibility. They must accept traffic from the internet, they run hardened vendor operating systems that most endpoint agents cannot inspect, and they are frequently patched less often than Windows servers because a reboot interrupts remote access for the whole company.
The two NetScaler flaws illustrate the problem well. CVE-2026-88771 is an improper input validation bug that enables remote code execution in a default configuration, with low attack complexity, so exploitation is reliable and does not depend on unusual settings. CVE-2026-88772 is a memory corruption flaw that requires the DTLS feature to be enabled and is harder to exploit, but it carries the same 9.5 severity. Both were used as zero-days, meaning defenders had no patch on the day attacks began.
This is part of a pattern. Earlier this month the industry watched legacy VPN and firewall flaws turn into ransomware entry points, and the same logic applies here: attackers prefer a single exposed device that gives them a foothold inside the network over a hundred phishing attempts. Patching alone cannot close the gap between first exploitation and vendor fix, so resilience has to be designed in.
What is a zero-day, and how is it different from a normal vulnerability? A zero-day is a flaw that attackers exploit before the vendor has released a fix, so defenders have had zero days to prepare. A normal, or n-day, vulnerability has a patch available, and the risk comes from how long an organization takes to apply it. Zero-days demand a different playbook: compensating controls, tight monitoring and the ability to isolate a device quickly, because waiting for a patch is not an option. The best enterprise programs prepare for both at once, with fast patching for known flaws and layered detection for unknown ones. That is why an internet-facing gateway should never be treated as a set-and-forget box. It needs an owner, a patch SLA, log forwarding to a SIEM and a tested plan for the day a critical advisory arrives on a Sunday night.
What should an enterprise do now? A disciplined response follows five steps.
Steps three and four are where most organizations struggle, because they need people who can read telemetry at any hour. A managed SOC with SIEM and MDR gives smaller IT teams that capability without building a night shift.
What do enterprises gain by treating the network edge as a managed service? First, speed. Organizations that keep an accurate appliance inventory and a pre-approved emergency change process can patch in hours instead of weeks, which is the difference between a scare and an incident.
Second, continuity. Remote access is business-critical, so teams delay patching to avoid downtime. A redundant design with multi-operator connectivity and SD-WAN lets you upgrade one gateway or one link while traffic flows through another, removing the excuse to wait. Dual appliances, diverse carriers and automatic failover turn a risky maintenance window into a routine one.
Third, accountability. Insurers, auditors and regulators increasingly ask how quickly a company patches actively exploited vulnerabilities. A documented process, with evidence from a KEV-driven patch policy, supports compliance and can reduce cyber-insurance friction.
Fourth, architecture. Moving from a single internet-facing VPN concentrator toward zero-trust access reduces how much a single flaw can expose. Identity-aware access, strong segmentation and continuous monitoring mean that one compromised appliance is an alert to triage, not a breach of everything behind it. Adding IT managed services for patching, configuration backup and lifecycle management keeps those controls current without consuming your internal team.
HIT Communications has spent more than 30 years operating enterprise networks in Latin America, the United States and Europe, and we see the same lesson repeat: security and connectivity fail together or hold together. Our teams combine managed security operations with carrier-grade connectivity so your remote-access edge is both protected and redundant.
For a NetScaler exposure review we can help you inventory and assess internet-facing appliances, apply emergency patches with a tested rollback plan, run compromise assessments through our SOC, and design redundant access using dedicated internet, SD-WAN and multi-operator links. For the longer term we build zero-trust access and monitoring so the next zero-day is a contained event.
We work with IT leaders in Colombia, Mexico, Panama, Spain, Brazil and the US, in English, Spanish and Portuguese, with one accountable partner across network, security and IT operations.
The NetScaler zero-days show that the most trusted device on your network can become the weakest one overnight. Patch to the fixed builds now, hunt for signs of prior compromise, rotate what the appliance touched, and then fix the structural issue: visibility, redundancy and a response process that does not depend on luck.
If you run NetScaler, or any internet-facing VPN, firewall or gateway, do not wait for the next advisory. Contact HIT Communications to schedule an edge-exposure review and build a patching and monitoring plan your leadership can verify.

Find out how we can transform your business. Talk to one of our experts now!
Get in touch