Keeping remote access secure takes time that IT teams would rather spend helping people work. When NetScaler advisories arrive close together, urgent updates and checks for signs of compromise can quickly take over the schedule.
What Is Happening with NetScaler
On September 27, 2026, Citrix published eight NetScaler CVEs and confirmed exploitation of CVE-2026-88771 and CVE-2026-88772. An October 3 bulletin followed for SAML-related denial of service. On October 8, another bulletin addressed remote code execution or denial of service, with version-specific SAML conditions.
Even when no breach is found, each urgent update means checking which systems are affected, planning the change and making sure everyone can sign in afterwards. That work takes time away from improving applications, testing recovery and everyday support.
Those hours belong in the cost of running a desktop platform, alongside licences and external support. Including maintenance time and business interruptions gives you a more useful comparison when considering a move to cloud desktops.
If an appliance has been compromised, recovery takes more than an update. Canada's Cyber Centre alert AL26-024 warns that persistence can survive patching. Investigation, evidence preservation and vendor remediation guidance still need attention while any migration is being planned.
Why Citrix Cloud May Leave the Dependency in Place
Moving to Citrix Cloud can reduce the infrastructure your team manages, but users may still connect through a NetScaler you operate. Citrix's DaaS security overview describes both a managed gateway service and an on-premises NetScaler gateway. The appliance's future depends on how that access is set up.
Keeping an existing gateway can help preserve familiar access arrangements. In Citrix's documented hybrid configuration, NetScaler continues handling authentication and authorisation while Citrix Gateway service carries desktop sessions. Your team still has an appliance to maintain and secure.
For businesses that still need Citrix, its Gateway service can replace the customer-managed gateway for supported desktop access. Reviewing how people actually connect helps establish whether the existing appliance can be retired as part of the move.
How AWS WorkSpaces and AVD Change Remote Access
AWS WorkSpaces
If your team already works with AWS, Amazon WorkSpaces is a sensible option to explore. Its Personal and Pools models offer persistent desktops or non-persistent environments, depending on how people need to work.
AWS runs the service's access infrastructure, including its streaming gateways. Desktop users can connect through that service, allowing a native WorkSpaces deployment to replace their NetScaler-dependent connection.
WorkSpaces Core needs separate consideration. Its shared responsibility model leaves brokering and gateways with customers or partners, so moving desktop hosting alone can leave that work with your team.
Azure Virtual Desktop
For businesses already using Microsoft identity and Windows applications, Azure Virtual Desktop is also worth exploring. It supports full desktops, RemoteApp applications and Windows Enterprise multi-session, giving you several ways to fit the service around how people work.
Microsoft runs the AVD web, broker and gateway services. Its default Reverse Connect approach avoids opening inbound ports for that connection. A native AVD setup can remove customer-managed gateway servers from desktop access.
Your team still looks after applications, identity, monitoring and recovery. AWS's security model retains customer responsibilities, and Microsoft leaves session hosts and supporting workloads under your control. The managed access services reduce the infrastructure you need to run, while those day-to-day tasks remain.
A small pilot before the next renewal gives you a practical way to explore either option. Try it with representative users and their everyday applications and peripherals, then compare performance and total cost. If it works well, expand gradually. Our cloud migration services can help with assessment, design, the pilot and the move to production.

Gonzalo Marsilli