ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • Online store
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Online store
  • Posts
    • All posts
    • Categories
    • Tags
    • Statuses
  • Solutions
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Repair Hacked Website
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

Citrix NetScaler Zero-Days: Why Perimeter Patching Is Not Enough

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. Citrix NetScaler Zero-Days: Why Perimeter Pat...
  • All articles
  • Categories
  • Tags
  • Statuses

Citrix NetScaler Zero-Days: Why Perimeter Patching Is Not Enough

A deadline that affects more than WashingtonCISA has given US federal agencies until 30 September to patch two critical vulnerabilities in Citrix NetS...

A deadline that affects more than Washington

CISA has given US federal agencies until 30 September to patch two critical vulnerabilities in Citrix NetScaler that are already being exploited in the wild. For systems administrators and hosting providers in Barcelona, Lleida, Tarragona or Girona, the federal deadline is a useful alarm clock rather than a rule that applies to them. NetScaler ADC and NetScaler Gateway sit at the edge of a great many corporate networks, publishing applications and brokering remote access. If your organisation runs one of these appliances, the clock is ticking for you too.

A glowing padlock and a curved shield deflecting key-shaped objects from a server rack

The two flaws, tracked as CVE-2026-88771 and CVE-2026-88772, are zero-days: attackers had a window to use them before a general fix existed. The first allows unauthenticated remote code execution on NetScaler ADC and Gateway running default configurations. In plain terms, an unpatched, internet-facing instance can be taken over without any credentials. The second can lead either to remote code execution or to denial of service, triggered by a memory overflow when DTLS is enabled — a setting that is often switched on by default on VPN virtual servers. That single detail turns many ordinary remote-access deployments into priority patching targets.

What Citrix has released, and what it means for you

Citrix has published updates for NetScaler ADC and NetScaler Gateway on the 14.1 and 13.1 branches, including FIPS and NDcPP builds. The minimum recommended versions are 14.1-73.37 and 13.1-64.23, plus their equivalents in certified editions. Secure Private Access Hybrid deployments that rely on NetScaler instances inherit the same exposure and should be treated as part of the same estate.

The security bulletin does not stop at those two CVEs. It also covers six further vulnerabilities, from CVE-2026-88773 to CVE-2026-88778, including HTTP request smuggling, policy bypass and TCP ISN prediction techniques. For the last of these, Citrix pairs the patch with a TCP configuration recommendation to mitigate specific scenarios where the affected functionality is in use. In other words, patching alone may not close every door: some environments need a configuration review as well.

Check for compromise before you close the door

CISA adds an uncomfortable nuance that security teams should take seriously: where feasible, look for signs of compromise before updating, and preserve forensic evidence if you suspect an intrusion. Applying the patch can reduce visibility into what happened, and in environments with limited telemetry, reviewing signals in NetScaler Console and bringing in specialist forensic analysis can be the difference between genuinely closing the hole and leaving a latent intrusion in place. For a Catalan SME or a regional hosting company, that may mean a short, deliberate pause before the maintenance window, not a delay of weeks.

Inventory first, urgency second

Outside the US federal scope, the message is the same but the sequence matters. Start with a complete inventory of every NetScaler instance you run, including the ones a subsidiary or a client forgot to mention. Then prioritise the internet-facing systems, check whether DTLS is active on VPN virtual servers, and plan maintenance windows with a rollback path ready, because upgrading this kind of infrastructure can involve downtime and sensitive changes in the data plane.

  • Locate all NetScaler ADC, Gateway and Secure Private Access Hybrid instances.
  • Rank them by exposure: internet-facing first, internal second.
  • Verify DTLS status on VPN virtual servers and document the result.
  • Prepare a rollback plan and a maintenance window before touching production.
  • Preserve logs and evidence if any sign of intrusion appears.

The version nobody wants to talk about

There is a final problem that haste cannot solve. NetScaler 12.1 and 13.0 are out of support and will not receive patches. If any part of your estate still runs those branches, the only realistic route is an urgent migration to a supported release. Keeping an unsupported edge appliance online in 2026 is not a calculated risk; it is an open invitation, and GDPR obligations around personal data make the consequences more than technical.

Patching is necessary, but it is not a strategy

Zero-days on perimeter appliances are a recurring theme, not a one-off event. The organisations that cope best are the ones that assume a patch will eventually arrive too late and build layers of defence around that assumption. Centralising protection across your servers is one of the most practical layers available. Abuse Shield, the ALMC service for server security, blocks malicious IPs automatically, manages fail2ban across multiple machines from a single point and shares an IP reputation feed between all your servers. When one host sees an attack, the others learn from it immediately.

That shared reputation model matters precisely in scenarios like this one. An attacker probing a NetScaler gateway in Lleida is often the same actor that will try a web server in Barcelona an hour later. If your machines operate in isolation, each one rediscovers the same threat. If they share intelligence, the first block protects the whole fleet. Combined with disciplined patching, a documented inventory and forensic readiness, it turns a frantic deadline into a manageable routine — and that is the real lesson behind CISA's 30 September date.

Related

  • How to Harden Your Servers with Fail2ban and IP Reputation Feeds
  • Fail2ban: Your First Line of Defense Against Unauthorized Server Access
  • Critical libssh2 flaw: urgent patch for SSH servers
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Security Audits and Pentesting
Cloud Migration (AWS, Azure, Google Cloud)
Backup & Disaster Recovery Plans
Virtualization & Containers (Docker, Kubernetes)
API Integrations & Microservices
Relacionados
  • Malicious PDFs: The Silent Threat to Your Servers
    Cybersecurity · 8 minutes ago
  • Citrix NetScaler zero-days: detect, patch and shield your servers
    Cybersecurity · 8 minutes ago
  • Exposed Vite Dev Servers: How Attackers Steal Cloud Secrets
    Cybersecurity · 1 day ago
  • InjectSetConsole: a stealthier path to remote code injection on Windows
    Cybersecurity · 3 days ago
  • Vibe Coding Security: 5 Questions to Ask Before Trusting an AI-Built App
    Cybersecurity · 4 days ago
  • CRA Compliance for Mobile Apps: A 2027 Guide for EU Businesses
    Cybersecurity · 4 days ago
Servidores MCP Destacados
  • Harness
    Official 🌟 Oficial
  • Phone Carrier Detector
    Other
  • Cycode
    Official 🌟 Oficial
  • Website to Markdown MCP Server
    Web Scraping
  • Jotdown
    Productivity
  • Healthcare RAG
    Other
  • Eka MCP Server
    Database
  • MCP Client Configuration Server
    Productivity
  • MCP Chain of Draft (CoD) Prompt Tool
    Development
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-29
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

SaaS Suite

  • PrintFlow (print shops)
  • WebTV (digital signage)
  • VeriFactu (invoicing)
  • Time tracking

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

Shall we talk directly?

Book an appointment in my calendar — I will call you or we can meet via Google Meet

  • ✓Instant confirmation via WhatsApp
  • ✓Real-time availability
  • ✓Reminder 1 hour before
  • ✓Cancel or reschedule with a single click
Initial consultation · 30min
📅 Check availability and book