Two critical Citrix NetScaler flaws, CVE-2026-88771 and CVE-2026-88772, were reportedly exploited before fixes were available. One allows unauthenticated command execution, while the other involves a memory overflow through DTLS, which is enabled by default for VPN virtual servers. Disabling DTLS does not address the command-execution flaw, and even builds that fixed an earlier authentication bypass remain affected. Since upgrading only establishes the fixed version and does not prove the appliance was never compromised, how are you balancing evidence collection against the need to patch quickly? Are you taking snapshots or collecting packet-engine core dumps before upgrading, and what checks are you using afterward to determine whether an appliance is clean?
1 Answer
If you have enough time to do it safely, preserve the appliance state before rebooting or upgrading: capture a snapshot according to your change procedure, collect the relevant logs and crash or packet-engine data, and record the running configuration and hashes. Then move to the fixed build as quickly as possible. If the device is internet-facing and exploitation is known to be active, I would prioritize containment and patching over a perfect pre-upgrade investigation, while preserving whatever telemetry is available elsewhere.

The main thing is not to treat a successful upgrade as proof that the box was clean. Review authentication, VPN, configuration-change, process, and outbound network activity from before the upgrade, and compare it with firewall and DNS logs.