July 23, 2026

Citrix just pushed out fixes for six vulnerabilities in NetScaler ADC and NetScaler Gateway. One of them carries a CVSS score of 8.8 out of 10. That's not a minor housekeeping update. That's the kind of score that means a real attacker can do real damage if you sit on it.
The two main risks here are arbitrary file reads and denial-of-service. Arbitrary file read sounds technical, but in plain terms it means an attacker can pull files off your system without logging in the normal way. Sensitive configs, credentials, internal data. Gone, without triggering most standard alerts. Denial-of-service means they can knock your gateway offline entirely, which for a company using NetScaler Gateway for remote access translates directly to people unable to work.
More companies than you'd think. NetScaler ADC and NetScaler Gateway show up a lot in mid-size offices that need load balancing, VPN access, or single sign-on for internal apps. If your company went through any kind of remote work expansion after 2020, there's a decent chance someone set up NetScaler Gateway as the front door for remote employees.
It also appears in healthcare, legal, and financial firms in the NJ/NYC area that have compliance requirements around remote access. If your IT setup was built by a vendor or consultant three or four years ago and you haven't audited it since, you might not even know it's there.
The vulnerabilities include insufficient input validation, which is a classic category of flaw. It basically means the software trusted data it should have questioned. Attackers can craft specific requests that exploit that trust to either extract files or overwhelm the system.
Citrix has released updated versions of NetScaler ADC and NetScaler Gateway. The fix is patching to those versions. There's no workaround that substitutes for the actual update here.
I've seen this pattern dozens of times. A vulnerability comes out, the vendor releases a patch the same day, and the affected business still hasn't applied it three weeks later. Sometimes it's because nobody owns the asset clearly. Sometimes the team is stretched thin. Sometimes there's anxiety about breaking something in production.
That gap between patch release and patch applied is where breaches happen. Attackers scan for unpatched systems fast. Within 24 to 72 hours of a public CVE, automated scanners are already probing for it. An 8.8 CVSS vulnerability on an internet-facing gateway is a high-priority target.
If your NetScaler appliance is managed, your vendor should already be on this. If you're self-managing it, you need to check the current version right now and compare it to Citrix's advisory.
First, find out if NetScaler ADC or NetScaler Gateway is in your environment. Check with whoever manages your network or remote access. If you're not sure, that's itself a problem worth solving.
Second, check the version. Log into the management interface and compare your build number to the patched versions listed in the Citrix security bulletin.
Third, schedule the update. Don't wait for your next maintenance window three weeks out. This one warrants a short-notice change. Plan for a maintenance window this week, test your remote access after the update, and confirm everything's working before you close the ticket.
Fourth, review who has access to the management interface. If the admin panel is exposed to the internet without an IP allowlist or MFA in front of it, that's a separate problem you should fix while you're in there.
Firewalls, load balancers, VPN gateways. These are the devices sitting at the edge of your network, and they're exactly what attackers go after first. They're often the least monitored and the most delayed when it comes to patching, because people are nervous about touching them.
Building a regular cadence for reviewing and patching edge devices, even just quarterly, would catch most of these before they become emergencies.
If you're not sure whether your NetScaler environment is up to date or who's responsible for it, Exine can take a look and help you get it sorted.