October 5, 2026
Citrix Patched Nine Flaws. Attackers Were Already Inside.
Citrix patched nine NetScaler flaws in a week and attackers got there first. What Florida businesses should check before trusting the patch.
Brian Lufkin Director of Operations
Reviewed by Reade Taylor, Founder & President Nine patched flaws, one bad week
Citrix published fixes for eight vulnerabilities in NetScaler ADC and NetScaler Gateway on September 27. Two of them scored 9.5 out of 10. One, CVE-2026-88771, allows remote code execution on any appliance running a default configuration, no password required. Both were already being used in live attacks before most administrators had read the bulletin.
Then it got worse. Early on Sunday, October 4, Citrix shipped an emergency patch for a ninth flaw, CVE-2026-88779, a memory bug in the SAML authentication component. That one was also under attack before the fix existed.
If your business uses NetScaler Gateway for remote access, or your IT provider manages one for you, the past seven days were a test. Not of the appliance. Of the people watching it.
The attacks started before the announcement
GreyNoise researchers observed exploitation attempts against CVE-2026-88771 days before Citrix published its bulletin. Mandiant and Google’s threat intelligence team traced exploitation of the second critical flaw, CVE-2026-88772, back to early September, and attributed it to suspected state-linked actors who planted web shells and moved laterally inside victim networks.
So the honest timeline reads like this. Attackers were working these boxes for weeks. Customers found out at the end of September.
The Shadowserver Foundation counted more than 20,000 potentially vulnerable NetScaler instances visible across North America and Europe. These are not obscure boxes. They sit in front of government agencies, financial services firms, law firms, and professional services companies, the exact organizations that hold money and client files. If that describes your business, our industry pages show how we approach each of those sectors.
CISA added the exploited flaws to its Known Exploited Vulnerabilities catalog and gave federal agencies until September 30 to patch. For the SAML flaw patched October 4, the deadline is October 7. Three-day federal deadlines are reserved for the fires actually burning.
Stuck on something like this right now?
Talk it through with a real US-based engineer, 24/7, no phone trees: (407) 587-0089.
Book a Free Strategy SessionPatching does not evict an intruder
The most important sentence in the guidance got the least attention: organizations should check whether they were compromised before upgrading, because patching an infected appliance may not remove the infection. Citrix released an indicator-of-compromise scanner and a file integrity monitor alongside the fixes for exactly this reason.
Think of it like changing the locks after a burglar copied your key. New lock, fine. If he is already in the house, the new lock changes nothing.
That turns this from a patching problem into a detection problem. An attacker who used CVE-2026-88772 in early September had weeks inside before a patch existed. The question that matters is not whether you patched. It is whether anyone reviewed what happened on that appliance between early September and patch day. That review work, reading authentication logs, hunting for web shells, flagging odd admin sessions and traffic to unfamiliar servers, is what managed detection and response teams do all day. Cyber Command runs a human-managed SOC with threat hunting, designed to catch the signals that follow an edge-device compromise rather than assuming the patch closed the book.
And if the scanner turns up evidence of compromise, treat it as an incident, not maintenance. Isolate the appliance, preserve the logs, and bring in incident response services before rebuilding, so you know what the intruder touched.
A Sunday patch is a staffing question
The October 4 fix landed early on a Sunday morning. Citrix said it had observed targeted attacks on unmitigated deployments. Administrators reported logs showing crafted login usernames carrying shell commands that downloaded a payload from an attacker-controlled server. Security researcher Kevin Beaumont then found one of his honeypots running a downloaded malware binary, which suggests these attacks go beyond knocking boxes offline.
Now the operational reality. Someone had to see that bulletin on a weekend, decide it mattered, snapshot the appliance, patch, verify the build, and read the logs afterward. The fixed builds are 14.1-73.41 and 13.1-64.28. At a company with one IT person, or a provider that answers tickets during business hours, none of that happens before Monday. Sometimes Wednesday.
This is the strongest argument for sharing the load. If you have an internal IT team, a co-managed IT arrangement keeps your people focused on the business while an outside bench covers the Sunday 6 a.m. bulletins. If you have no IT staff at all, 24/7 coverage through managed security services exists precisely because attackers prefer weekends.
The silence test
Here is a simple way to grade your current IT arrangement against this week. Did anyone tell you about it?
If NetScaler sits anywhere in your stack and you heard nothing by Monday morning, that silence is information. Not proof of negligence. But worth a direct question: what did you do about the Citrix zero-days, and when? A provider doing this well answers with specifics in five minutes. Builds, dates, scanner results.
We hear from Florida businesses in this position regularly, and the pattern is rarely one dramatic failure. It is quiet weeks like this one, where nothing was said and nothing was checked, stacking up until trust runs out. If this week put that question in your head, our guide to switching IT providers walks through what a clean transition looks like, including co-managed options and how to leave a provider that handles departures badly, without onboarding fees.
What to do this week
Even if you never touch the appliance yourself, you can drive this from the owner’s seat.
First, find out whether NetScaler ADC or Gateway exists anywhere in your environment, and ask your key vendors the same question, since their compromise becomes your problem. Second, get the build numbers in writing and confirm they are 14.1-73.41, 13.1-64.28, or later. Third, ask whether Citrix’s compromise scanner was run and what it found, with logs reviewed back to early September, not just patch week. Fourth, ask who reviews network security bulletins on weekends, and listen carefully to the answer.
None of this requires technical depth. It requires someone on your side who treats an edge device like the front door it is.
Cyber Command is a US-based team headquartered in Winter Springs, serving Orlando, Tampa Bay, and Jacksonville. Real engineers answer 24/7, with no phone trees and no ticket black holes. If you want a second set of eyes on your remote access setup after this week, reach out or call (407) 587-0089.
#CyberSecurity #ManagedIT #Citrix #ZeroDay #IncidentResponse
This article is for general informational purposes only and is not legal, compliance, insurance, or other professional advice. Threats, technologies, and regulations change quickly; confirm current requirements with your own advisors before acting. See our full disclaimer.