Oct 1, 2026 · 5 min read

Collect the NetScaler evidence before the upgrade reboots it

Citrix tells you to patch the exploited NetScaler now. Its own IR playbook and CISA both put evidence collection first.

Article header: Collect the NetScaler evidence before the upgrade reboots it

On September 27, 2026, Cloud Software Group published CTX697096, closing eight NetScaler ADC and NetScaler Gateway CVEs and stating that "Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed." CISA added both CVEs to the Known Exploited Vulnerabilities catalog the same day with a remediation due date of September 30 — three days. The bulletin tells customers to install the updated versions "as soon as possible": 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 for 13.1-FIPS and 13.1-NDcPP.

The upgrade is the thing that discards the evidence

CVE-2026-88771 is scored CVSS v4.0 9.5, and its precondition column reads "All NetScaler ADC and NetScaler Gateway deployments (Default configuration / No additional feature required)." On NetScaler advisories the precondition clause normally decides which CVEs apply to you; this one narrows nothing. If the appliance was reachable and unpatched, it was in scope, and exploitation had already been observed.

So the change ticket writes itself — upgrade tonight. The problem is what the upgrade does. A firmware upgrade reboots the appliance, and the packet-engine process memory, where an unauthenticated RCE against a default-configuration NetScaler would have landed, does not survive a reboot.

Cloud Software Group has a second document saying to collect that memory first. CTX694799, "Steps to Take if NetScaler ADC is Suspected to be Compromised," was published on May 13, 2026 — 137 days before the bulletin. Step 1 is Preserve Evidence: snapshot the VPX, document system time, timezone and NTP configuration before isolation, preserve remote syslog and NetScaler Console logs alongside local ones, generate a support bundle and a packet-engine core dump, and bit-for-bit image MPX/SDX disks behind a write blocker. The firmware upgrade is an unnumbered subheading inside step 5, Rebuild and Restore, reached after isolate, revoke credentials and investigate connected systems: "After wiping or rebuilding, upgrade the NetScaler ADC to the latest available version of firmware before restoring the configuration backup."

Two details shape the decision. The packet-engine core dump is itself destructive to availability — "The system will perform a warm restart during this process and SSH connections will disconnect." And Cloud Software Group states in writing that it "does not support forensic investigations." Whoever reads the image is not the vendor.

CTX697096 does not link to CTX694799. The only document that cites both is the KEV entry.

Timeline of four dated events. May 13, 2026: Citrix publishes CTX694799, the NetScaler compromise playbook, whose step 1 is preserve evidence. June 10, 2026: CISA issues BOD 26-04 and its forensic triage implementation guidance, which puts evidence collection at step 2 and patching at step 3. September 27, 2026, 137 days after CTX694799: Citrix publishes CTX697096 for eight CVEs and CISA adds CVE-2026-88771 and CVE-2026-88772 to KEV. September 30, 2026, three days later: the federal remediation due date.

The sequencing is published — just not by Citrix

The KEV requiredAction for both CVEs is not "patch." It reads: "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 ... guidance and CISA's 'Forensics Triage Requirements'." Both entries carry forensicTriage: "Yes", and the directive defines what that obliges: "the agency must complete remediation or mitigation action within the timeline (three days) and carry out a forensic triage of the asset to assess whether the system is compromised."

The implementation guidance CISA issued with BOD 26-04 on June 10, 2026 then answers the order outright, in numbered steps keyed to hours since the KEV addition:

Step 1  Scoping                            first 2 hours
Step 2  Preserve and Collect Evidence      2-24 hours
        "Prioritize immediate acquisition of volatile data."
        "Do not alter or remediate systems prior to
         evidence/artifact collection when possible."
Step 3  Critical Patching and Stabilization  2-24 hours
        "Collect all required evidence prior to this step as
         patching may jeopardize the availability of artifacts."
Step 4  Contain and Control                6-24 hours
        "Premature containment can destroy vital evidence."

Note that CISA and Citrix disagree downstream: CISA patches at step 3, before containment, while CTX694799 upgrades firmware only after the wipe — the same shape as Cisco's rebuild rather than upgrade for a suspected email gateway. They agree completely on what comes first.

Write that order down per appliance now, while nothing is on fire: who authorises a snapshot without a change board, where the memory image is written and how long it is kept, and which incident response firm gets the call — because the vendor has said it is not them, and a retainer negotiated mid-incident costs more and arrives later. If law enforcement may be involved, CTX694799 adds that "evidence preservation requirements may supersede operational recovery needs," which is a legal call, not an engineering one.

The cost is real and it is availability. Preservation on a device in the traffic path means a snapshot plus a warm restart before the upgrade window opens, on top of the upgrade's own reboot. There is a legitimate way to buy the time: BOD 26-04 states that "one valid mitigation is to remove the system from the internet; that action changes the value of 'Publicly Exposed' from Yes to No and will shift the required timeline for further action." Taking the appliance offline is a mitigation, not a delay.

If full preservation is not achievable, take the cheap half. The VPX snapshot, the remote syslog pull and the support bundle cost minutes and no reboot, and are the artifacts most likely to be gone next week. Skip the packet-engine core dump if no one is going to analyse it — an unread memory image is a reboot you paid for twice. BOD 26-04 binds federal civilian agencies; if yours is not one the three-day clock does not apply, but its sequencing is still the only published answer to the question.

What to check this week

  • For each internet-facing NetScaler, record the running build and whether it is at or past 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279.
  • Name, in writing, the person who can authorise taking an appliance out of the traffic path without waiting for a change board.
  • Confirm where NetScaler syslog is shipped off-box and how long it is retained. Local logs die with the appliance.
  • Check whether you have an incident response firm under retainer who will accept a NetScaler VPX snapshot and an NSPPE- core file.
  • Confirm NetScaler management services are not reachable from the public internet — CTX694799 flags this separately and it is independent of any of these eight CVEs.

North InfoSec runs AI-assisted penetration testing and security assessments, including the edge-appliance exposure review described above. northinfosec.com

← All articles