Patching NetScaler ADC and NetScaler Gateway is urgent, but it is not the same as incident closure. Citrix says CVE-2026-88771 and CVE-2026-88772 have been exploited and explicitly warns that installing an update does not remove compromise artifacts or prove that exploitation did not occur before remediation.
The investigation should answer three questions: was the appliance exposed during the vulnerable window, is there evidence of unauthorized activity, and which credentials, certificates, or downstream systems must be considered untrusted?
Preserve evidence before rebooting
Start with a timestamped collection of the running configuration, system and audit logs, authentication events, crash artifacts, process and network state, filesystem metadata, and available packet or flow telemetry. Export data from every HA member. A quiet standby may still contain different artifacts or an older vulnerable image.
Collect external evidence as well: firewall, WAF, load-balancer, DNS, identity-provider, VPN, EDR, and SIEM records. Appliance-local logs can be altered or rotated, while upstream records may retain the requests and outbound connections needed to reconstruct the timeline. Preserve time-zone settings and clock drift so events can be correlated accurately.
Document every collection action and hash exported artifacts. Avoid destructive cleanup until the evidence set is complete. If the appliance is actively communicating with suspicious infrastructure, isolate it through an upstream control rather than improvising changes on the potentially compromised host.
Use Citrix IoC scanning as a starting point
Citrix provides generic Indicators of Compromise through the NetScaler Console Security Advisory workflow. The capability is available in the NetScaler Console service and on-premises Console with Cloud Connect, beginning with 14.1-73.36, and requires the telemetry channel. Organizations unable to use it can contact Citrix Support for access to the applicable checks.
The vendor also cautions that the detection logic cannot cover every attacker technique and may have limited forensic value. A clean scan is not proof of absence. Use it to prioritize deeper review, not to replace the investigation. Retain scan results and the date of the detection logic because Citrix may update the rules later.
Hunt beyond static indicators
Review the exposure window for unexpected administrative logins, configuration changes, new files in web-accessible directories, altered startup behavior, unusual child processes, shell execution, and outbound HTTP, HTTPS, DNS, or SSH connections. Compare file integrity and configuration with a known-good appliance of the same release, while accounting for legitimate local customizations.
Correlate VPN and AAA activity with identity-provider logs. Look for logins outside user patterns, changes to SAML or LDAP configuration, new authentication policies, anomalous session creation, and access from infrastructure not normally used by administrators. Sudden log gaps, cleared history, or time changes are themselves investigation leads.
Citrix recommends forwarding NetScaler logs to an external SIEM and using Console File Integrity Monitoring. If those controls were not enabled before the incident, record the visibility gap honestly; enabling them after patching improves future detection but cannot recreate lost evidence.
Scope secrets and trust relationships
A NetScaler may hold or access TLS private keys, SAML service-provider material, LDAP bind credentials, RADIUS shared secrets, administrative passwords, API keys, SNMP credentials, and certificates used for backend authentication. Inventory these relationships before rotating anything so the response does not break every application at once.
Prioritize credentials that were stored on the appliance, reusable across systems, or capable of administrative access. Coordinate certificate replacement with application and identity teams. Review the issuing CA and certificate inventory for unauthorized requests. Invalidate sessions and tokens where the architecture allows it, and monitor for continued use of retired secrets.
Rebuild when integrity is uncertain
Citrix’s additional guidance recommends deploying a new, updated NetScaler instance when compromise is suspected or confirmed. That is the safer path because patching vulnerable code does not remove persistence or restore trust in the existing filesystem.
Build from a verified image, restore only reviewed configuration, replace exposed secrets, and validate the new instance before returning traffic. Keep the original system isolated for forensic work. If rapid replacement is not possible, document the temporary controls and the explicit risk owner.
Close the incident with a decision record
The closure package should include exposure dates, preserved evidence, IoC scan version and result, behavioral hunting results, affected accounts and secrets, rebuild or retain decision, and monitoring actions. Separate “no indicators found” from “not compromised”: the former is an evidence statement; the latter requires sufficient telemetry and analysis to support it.

