NCSC Urges UK organizations to Patch for Citrix NetScaler ADC and Gateway 0-Day Vulnerabilities
The UK NCSC urged immediate patching after two critical Citrix NetScaler zero-days were exploited for unauthenticated remote code execution.
The UK NCSC urged immediate action on eight Citrix NetScaler ADC and Gateway flaws, two of which are already exploited. CVE-2026-88771 and CVE-2026-88772 are rated CVSS 4.0 9.5: the first is unauthenticated remote command execution on default configurations, and the second is a memory overflow that can yield remote code execution or denial of service when DTLS is enabled. Six additional issues, CVE-2026-88773 through CVE-2026-88778, are also fixed. Affected on-premises releases include 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, and CISA has added the two critical bugs to the Known Exploited Vulnerabilities catalog.
- CVE-2026-88771 allows unauthenticated remote command execution on default NetScaler setups.
- CVE-2026-88772 can cause remote code execution or denial of service with DTLS.
- Both critical flaws are exploited; CISA added them to the KEV catalog.
- Fixed builds include 14.1-73.37 and 13.1-64.23; six further flaws are patched.
- NCSC advises isolating appliances, preserving evidence, patching, then threat hunting.
Vulnerabilities mentionedAll →
- CVE-2026-84528.81%Memory Buffer Overflow in Citrix NetScaler ADC/Gateway Exploited in the Wildpublished · Citrix NetScaler ADC KEV PoC
Full article657 words · extracted from cybersecuritynews.com · click to collapse
The UK National Cyber Security Center (NCSC) has urged organizations to take immediate action against eight vulnerabilities affecting customer-managed Citrix NetScaler ADC and NetScaler Gateway appliances.
Two critical flaws, CVE-2026-88771 and CVE-2026-88772, are already being exploited against unmitigated systems, turning routine patching into an urgent incident-response task.
Citrix NetScaler 0-Day Vulnerabilities
Citrix’s CTX697096 bulletin rates both exploited vulnerabilities at 9.5 under CVSS 4.0. CVE-2026-88771 is an improper input-validation flaw that enables an unauthenticated, remote attacker to execute arbitrary commands.
It affects every vulnerable NetScaler deployment, including default configurations, without requiring an optional feature. CVE-2026-88772 is a memory-overflow issue that can cause remote code execution or denial of service when DTLS is enabled; DTLS is enabled by default on VPN virtual servers.
The update also addresses six additional weaknesses. CVE-2026-88773, rated 9.3, permits HTTP request smuggling where HTTP configurations are enabled. CVE-2026-88774 can bypass feature policies that use HTTP URL-based expressions.
CVE-2026-88775, CVE-2026-88776 and CVE-2026-88777 are memory-overflow vulnerabilities affecting, respectively, Gateway or AAA virtual servers, Oracle load-balancing virtual servers, and LB/CS or CGNAT-LSN/NAT64 systems using non-HTTP Layer 7 features.
CVE-2026-88778 allows TCP initial sequence number prediction when Enhanced ISN Generation is disabled.
Affected on-premises releases are NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS, and 13.1-FIPS or 13.1-NDcPP before 13.1-37.279.
Secure Private Access Hybrid deployments using NetScaler instances are also exposed. Citrix-managed cloud services and Adaptive Authentication are being upgraded by Cloud Software Group.
According to the advisory published by the NCSC, the agency recommends reading Citrix’s bulletin and accompanying blog, identifying exposed appliances and temporarily isolating affected systems where practical.
Defenders may block access with upstream firewalls, disable vulnerable components, or restrict connections to approved organizational IP ranges.
They should then preserve evidence, investigate with Citrix’s published indicators of compromise, install the appropriate fixed build, verify every node, and only then restore service. UK victims should report confirmed compromises through the government’s cyber-incident reporting service.ncsc
Because NetScaler appliances commonly sit at the network edge and broker trusted VPN, application and authentication traffic, successful exploitation can give adversaries a valuable foothold for credential theft, persistence and lateral movement into internal environments.
After safely reintroducing patched systems, organizations should keep monitoring Citrix’s bulletin, repeat threat hunts as intelligence develops, and validate that update levels remain consistent across high-availability pairs.
Patching alone cannot establish that an appliance was never breached. Security teams should inspect authentication and network activity, unexpected files, processes, configuration changes, and outbound connections, while forwarding logs to an external SIEM.
NetScaler Console’s Security Advisory workflow provides generic IOC checks when telemetry is enabled, and File Integrity Monitoring can flag unauthorized changes; Citrix cautions that automated checks may not identify every attacker technique.
Administrators should also treat CVE-2026-88778 separately by enabling Enhanced ISN Generation as directed, because the TCP configuration change is required in addition to software updates.
For 13.1 systems, running the show ns variable before upgrading is prudent: Citrix guidance cited by Cyber Security News warns that systems with configured variables may require 13.1-64.24 to avoid a reboot loop.
Cyber Security News previously alerted readers when researchers first reported two undisclosed NetScaler RCE zero-days, then covered Citrix’s confirmation, CVE assignments, and emergency fixes.
CISA has added two critical Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities catalog after evidence showed they were being actively exploited in attacks.
Its recent Citrix coverage also includes exploited CVE-2026-8452 and the 2025 CitrixBleed 2 campaign, reinforcing a familiar lesson: internet-facing edge appliances demand rapid asset discovery, forensic triage, patching, and continuous threat hunting.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.