When an internet-facing appliance is confirmed as exploited before a fix exists, installing the update is the last step of the response. I think most teams still treat it as the whole response, and the UK National Cyber Security Centre’s latest NetScaler alert shows why that habit is out of date.

What the NCSC actually told defenders to do

On September 28 the NCSC published an alert on Citrix NetScaler ADC and Gateway. Citrix had issued a security bulletin covering eight vulnerabilities, and the NCSC says two of them, CVE-2026-88771 and CVE-2026-88772, are confirmed as actively exploited. CVE-2026-88771 allows an unauthenticated remote attacker to execute arbitrary commands, according to the NCSC. The CISA Known Exploited Vulnerabilities catalog added both on September 27 with a due date of September 30 and a forensic triage requirement.

The order of the NCSC’s priority actions is the point. First, read the bulletin and check whether you run an affected version. Second, “if possible”, isolate the affected system and replace it with a new, fully up-to-date system. Third, investigate for evidence of compromise using the published indicators. Fourth, install the latest updates. Only then re-enable the service. Patching is fourth on a list of six, and the alert says the replacement step may cause a service outage.

Media Partner

Web3 x AI Fusion — Media Partner

Why replacement beats patching for an exploited edge device

A patch fixes the flaw. It does nothing about what an attacker did with the flaw beforehand. On an appliance that terminates remote access and sits between the internet and internal systems, a successful unauthenticated command execution gives an attacker a foothold on a device at the network edge. If the exploitation preceded the patch, updating the software leaves whatever the attacker left behind in place.

The CISA catalog entry points the same direction. It requires forensic triage for both flaws and tells stakeholders to discontinue use of the product if mitigations are unavailable. I read that as the government stating openly that “patched” and “clean” are separate conditions and that the second one has to be demonstrated.

The NCSC has also described a broader pattern. In its August advisory on disruptive cyber activity and edge devices, it says it continues to see activity aimed at internet-exposed systems and edge devices across all sectors and urges organizations to keep an accurate inventory of what faces the internet. An organization that cannot list its edge appliances cannot replace them on short notice either.

The strongest objection

The fair objection is cost. Replacing a production gateway means an outage, a rebuilt configuration and a change window, and the NCSC itself warns of the disruption. Many teams will judge that a patch and a scan of the indicators is a proportionate response, particularly when they have no evidence of compromise.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

I accept the cost and disagree with the conclusion. Clean indicators are weak comfort when exploitation predates the fix, because an appliance that was exploitable cannot vouch for its own logs. Our earlier analysis of the NetScaler disclosure timeline reported that exploitation ran for weeks before a patch existed. For a defender, the weeks before the fix are the weeks that need investigating. An outage you schedule costs less than one an attacker chooses, and the NCSC’s own ordering puts the planned outage first.

What it means for the security leader

Treat edge appliances as disposable infrastructure. That has three practical consequences.

  • Keep a rebuild path. Store the configuration as code and maintain a tested procedure, or a spare appliance, so that replacing a gateway takes hours and not a project.
  • Split the response into two questions. Whether you are patched and whether you are clean need separate owners and separate evidence. Only the first question is answered by a version number.
  • Measure the window. Track the time from public exploitation to the day your appliance was rebuilt or verified, not only the time to patch. Our piece on CISA patch deadlines outrunning adoption shows how far apart those two numbers can sit.

What to do this week

List every NetScaler ADC and Gateway you operate and compare the versions with the NCSC’s affected list: 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, plus the FIPS builds named in the alert. Run the vendor’s published indicators on each one. Where an appliance was reachable from the internet before it was updated, plan its replacement, and start with the unit that fronts remote access. Register for the NCSC Early Warning service if you are in the UK. And write down the rebuild time you measure, because that number is your real recovery capability for the next edge flaw.

Source: NCSC, Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway