Citrix NetScaler Zero-Days Under Attack: What Indian IT Teams Must Do Now
Citrix has confirmed active exploitation of two critical vulnerabilities in NetScaler ADC and NetScaler Gateway. The flaws were being exploited as zero-days, meaning attacks were already taking place before fixes were available. For Indian organisations using NetScaler for remote access, this makes immediate patching a priority.
The two vulnerabilities, CVE-2026-88771 and CVE-2026-88772, can allow remote code execution. Citrix has released patched versions, including 14.1-73.37 and 13.1-64.23, along with relevant FIPS builds. Organisations should identify affected appliances and update them as soon as possible.
Because NetScaler gateways can sit at the network perimeter and provide remote access to internal systems, a compromised appliance could create a pathway into an organisation's network. IT teams should therefore treat exposed and unpatched systems as a potential security incident and review available logs for signs of compromise.


This incident highlights why organisations need security at multiple layers. Net Protector Endpoint Security and EDR solutions can provide additional protection for endpoints and help security teams detect suspicious activity beyond the network gateway.