← All posts

“We Patched” Is Not the Same as “We’re Safe”: The Citrix NetScaler Lesson

If your security team told you last week that the Citrix NetScaler problem was handled because the patch was installed, this week's news should change the follow-up question you ask.

In late September, Citrix released fixes for eight vulnerabilities in NetScaler ADC and NetScaler Gateway, the appliances many companies use to let employees and partners connect to internal systems. Two of those flaws, tracked as CVE-2026-88771 and CVE-2026-88772, were already being exploited by attackers when the fixes shipped. Both carry a severity score of 9.5 out of 10. CISA, the U.S. government's cyber defense agency, added both to its Known Exploited Vulnerabilities catalog and told organizations to review Citrix's advisories right away.

Then it got worse. As of this morning, SecurityWeek reports that a third NetScaler flaw, CVE-2026-88779, is being exploited, and that security researcher Kevin Beaumont observed attacks against honeypot systems that already had the earlier patches applied. Citrix has described the impact as targeted attacks that can cause denial of service, though SecurityWeek notes there are indications of something more serious. CISA has added the new flaw to its catalog, the sixth NetScaler vulnerability it has listed this year, according to SecurityWeek.

The Part Executives Miss

Here is the distinction that matters for the boardroom. The new flaw is a different bug. Patching the first two did not protect anyone from the third. But from a business standpoint, that is a technicality. The company that "finished patching" is still being attacked on the same device, and the attackers are not waiting for the next maintenance window.

There is a second, quieter problem. Mandiant's Charles Carmakal has warned that patching alone may not remove an intruder who got in first. Google's threat intelligence group and Mandiant traced exploitation of one of the two original flaws back to early September, which means attackers had weeks of access before most customers even knew a fix existed. In Carmakal's words, "patching without taking the other steps might not resolve the infection." Researchers described web shells (hidden remote-control programs) planted on compromised appliances, and attackers moving from there into internal networks.

So "patched" can mean two very different things: the door is now locked, or the door is locked and nobody has checked whether someone is already inside.

Why This Is a Board Issue

In Cyber Risk Is Business Risk, I argue that boards should stop asking whether a specific tool or patch is in place and start asking three questions: What are we trying to protect? How would we know if we were compromised? And what would we do if we were? The NetScaler story lands squarely on the second and third.

A patch status report answers none of them. It tells you about the lock, not about whether anyone has already walked through the door. This is the compliance-versus-security gap in its purest form. A ticket marked "closed" satisfies an audit checklist. It does not tell you whether an attacker is sitting on a device that sits at the edge of your network.

It also raises a personal-accountability question. Directors have a duty to oversee material risks, and a remote access appliance exposed to the internet is exactly the sort of asset that, if compromised, becomes a material event. If the board was told "we patched" and it later emerges that the company was breached through that very device weeks earlier, the question regulators and plaintiffs will ask is what the board asked in response.

What to Ask Your CISO This Week

  1. Do we run NetScaler or Citrix Gateway, and where? Insist on a complete answer, including systems run by subsidiaries, acquired companies, and vendors who connect to us.
  2. Did we check for compromise, or only apply the patch? Ask specifically whether the team used the scanner and file integrity tools Citrix provided and looked for unexpected administrator sessions and outbound connections. Government and vendor guidance recommended checking for signs of compromise, and preserving forensic evidence, before updating.
  3. How fast can we respond to a third wave? If CISA's deadline for the newest flaw is as close as reported (federal agencies were given until October 7), what is our own deadline, and who owns it?
  4. Does this device need to face the internet at all? If it must, what limits what an attacker can reach from it? One compromised appliance should not be a master key.
  5. Who is our backup if the vendor's support is overloaded? SecurityWeek reported that administrators faced hours-long support queue delays. Your plan should not depend on a vendor answering the phone during an industry-wide incident.

The Takeaway

Edge devices like VPN gateways and application delivery controllers are attractive because they sit between the internet and everything you own, and they run with high privileges. Attackers know this, and the pace of NetScaler exploitation this year shows they will keep hammering the same targets.

You do not need to understand the technical details of a memory overflow to govern this risk. You need to make sure your organization measures the right thing. Stop asking "Are we patched?" Start asking "Do we know we weren't already compromised?" The difference between those two questions is the difference between compliance and security.