Wednesday, September 30, 2026 Newsletter Advertise
Breaking
Cyber

BreakingNCSC warns of active exploitation in Citrix NetScaler flaws

The UK cyber agency says two of eight newly disclosed Citrix NetScaler ADC and Gateway vulnerabilities are being actively exploited and urges immediate mitigation.

NCSC warns of active exploitation in Citrix NetScaler flaws. Source: NCSC (UK)

The UK National Cyber Security Centre issued an alert on 28 September 2026 urging organisations to promptly mitigate eight vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway, two of which it said have been confirmed as actively exploited.

What has happened

According to the NCSC, Citrix has published a security bulletin detailing eight vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. The agency said two of them, CVE-2026-88771 and CVE-2026-88772, have been confirmed as being actively exploited.

The NCSC described CVE-2026-88771 as improper input validation allowing an unauthenticated remote attacker to execute arbitrary commands, and CVE-2026-88772 as an improper restriction of operations within the bounds of a memory buffer, leading to remote code execution or denial of service.

The remaining issues include CVE-2026-88773, an HTTP request/response smuggling flaw that may allow an attacker to manipulate or bypass security controls; CVE-2026-88774, an improper HTTP URL-based expression usage leading to a feature policy bypass; CVE-2026-88775, CVE-2026-88776 and CVE-2026-88777, memory overflow vulnerabilities that may result in unpredictable or erroneous behaviour or denial of service; and CVE-2026-88778, a predictable exact value vulnerability that may allow an attacker to influence integrity or availability.

The NCSC said it is working to understand the impact of these vulnerabilities on UK organisations.

Who is affected

The alert says organisations using Citrix NetScaler ADC or Citrix NetScaler Gateway on premises are affected.

The NCSC listed the following supported customer-managed versions as affected: Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 before 14.1-73.37; 13.1 before 13.1-64.23; Citrix NetScaler ADC FIPS before 14.1-73.37 FIPS; and Citrix NetScaler ADC FIPS and NDcPP before 13.1-37.279.

What the NCSC recommends

The NCSC recommends following vendor best practice advice to mitigate vulnerabilities, and set out a series of priority actions for network defenders.

These include reading the Citrix security bulletin and accompanying blog, which the NCSC said includes indicators of compromise, in full; isolating affected systems where possible and replacing them with new, fully up-to-date systems, while noting this may cause service outage; investigating for evidence of compromise using the published IoCs; installing the latest available updates; and re-enabling affected systems.

The agency also advised continued monitoring of the Citrix security bulletin and continuous threat hunting, and said customers can use NetScaler Console File Integrity Monitoring to help detect unauthorised or unexpected changes to monitored files on managed NetScaler instances. Organisations in the UK that believe they have been compromised should report it, and can also report to the vendor to assist its investigation.

The NCSC pointed to its own guidance on vulnerability management and preventing lateral movement, its free Early Warning service for UK organisations, and its Vulnerability Disclosure Toolkit.

What to do

  • Read the Citrix security bulletin and accompanying blog in full, including the indicators of compromise, to determine whether you run an affected system.
  • Where possible, isolate affected systems and replace them with new, fully up-to-date systems; the NCSC notes this may cause a service outage.
  • As interim measures, temporarily disable access to the service with upstream firewalls, disable the vulnerable components, or restrict access to your organisation's IP range.
  • Investigate thoroughly for evidence of compromise using the published IoCs.
  • Install the latest available updates, then re-enable or reintroduce the affected systems.
  • If you believe you have been compromised and are in the UK, report it; you can also report to Citrix to assist its investigation.
  • Keep monitoring the Citrix bulletin, continue threat hunting, and consider NetScaler Console File Integrity Monitoring to spot unexpected file changes.
  • UK organisations can sign up for the free NCSC Early Warning service, or check the MyNCSC portal if already enrolled.
Key facts and where they come from
  • Citrix published a bulletin covering eight vulnerabilities in NetScaler ADC and Gateway.
    Citrix has published a security bulletin detailing eight vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • Two of the flaws are confirmed as actively exploited.
    Two of these, CVE-2026-88771 and CVE-2026-88772, have been confirmed as being actively exploited.
  • CVE-2026-88771 allows unauthenticated remote command execution.
    CVE-2026-88771: Improper input validation allowing an unauthenticated remote attacker to execute arbitrary commands.
  • CVE-2026-88772 can lead to remote code execution or denial of service.
    CVE-2026-88772: Improper restriction of operations within the bounds of a memory buffer, leading to remote code execution or denial of service.
  • Affected versions include 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23.
    Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 before 14.1-73.37 Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 before 13.1-64.23
  • On-premises deployments are affected.
    Organisations using Citrix NetScaler ADC or Citrix NetScaler Gateway on premises are affected.
  • The NCSC is still assessing UK impact.
    The NCSC is working to understand the impact of these vulnerabilities on UK organisations.

Read the original from NCSC (UK) →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Cyber