Critical vulnerabilities in NetScaler ADC and NetScaler Gateway require a structured response: assess exposure, select a secure target build, update the systems and then check for indicators of compromise.
This checklist summarizes the key steps for new NetScaler CVEs. The current vendor security bulletin, supported firmware releases and the specifics of the environment always remain authoritative.
Assess the CVE and prepare the update
For CVE-2026-8452, additionally document whether and during which period the appliance was publicly accessible as a Gateway or AAA virtual server. Record the build that was running at the time and the exact upgrade date. According to Citrix, affected versions include NetScaler ADC and NetScaler Gateway before 14.1-72.61 and before 13.1-63.18.
- Review the security bulletin and identify affected product versions.
- Document the current build, HA status, partitions and enabled features.
- Check the supported target release, known issues and upgrade paths.
- Back up the configuration and system files and define a reliable rollback plan.
- Implement and document vendor-provided workarounds until the update is completed.
