NCSC Urges UK organizations to Patch for Citrix NetScaler ADC and Gateway 0-Day Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


The UK National Cyber Security Center (NCSC) has urged organizations to take immediate action against eight vulnerabilities affecting customer-managed Citrix NetScaler ADC and NetScaler Gateway appliances.

Two critical flaws, CVE-2026-88771 and CVE-2026-88772, are already being exploited against unmitigated systems, turning routine patching into an urgent incident-response task.

Citrix NetScaler 0-Day Vulnerabilities

Citrix’s CTX697096 bulletin rates both exploited vulnerabilities at 9.5 under CVSS 4.0. CVE-2026-88771 is an improper input-validation flaw that enables an unauthenticated, remote attacker to execute arbitrary commands.

It affects every vulnerable NetScaler deployment, including default configurations, without requiring an optional feature. CVE-2026-88772 is a memory-overflow issue that can cause remote code execution or denial of service when DTLS is enabled; DTLS is enabled by default on VPN virtual servers.

The update also addresses six additional weaknesses. CVE-2026-88773, rated 9.3, permits HTTP request smuggling where HTTP configurations are enabled. CVE-2026-88774 can bypass feature policies that use HTTP URL-based expressions.

CVE-2026-88775, CVE-2026-88776 and CVE-2026-88777 are memory-overflow vulnerabilities affecting, respectively, Gateway or AAA virtual servers, Oracle load-balancing virtual servers, and LB/CS or CGNAT-LSN/NAT64 systems using non-HTTP Layer 7 features.

CVE-2026-88778 allows TCP initial sequence number prediction when Enhanced ISN Generation is disabled.

Affected on-premises releases are NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS, and 13.1-FIPS or 13.1-NDcPP before 13.1-37.279.

Secure Private Access Hybrid deployments using NetScaler instances are also exposed. Citrix-managed cloud services and Adaptive Authentication are being upgraded by Cloud Software Group.

According to the advisory published by the NCSC, the agency recommends reading Citrix’s bulletin and accompanying blog, identifying exposed appliances and temporarily isolating affected systems where practical.

Defenders may block access with upstream firewalls, disable vulnerable components, or restrict connections to approved organizational IP ranges.

They should then preserve evidence, investigate with Citrix’s published indicators of compromise, install the appropriate fixed build, verify every node, and only then restore service. UK victims should report confirmed compromises through the government’s cyber-incident reporting service.ncsc

Because NetScaler appliances commonly sit at the network edge and broker trusted VPN, application and authentication traffic, successful exploitation can give adversaries a valuable foothold for credential theft, persistence and lateral movement into internal environments.

After safely reintroducing patched systems, organizations should keep monitoring Citrix’s bulletin, repeat threat hunts as intelligence develops, and validate that update levels remain consistent across high-availability pairs.

Patching alone cannot establish that an appliance was never breached. Security teams should inspect authentication and network activity, unexpected files, processes, configuration changes, and outbound connections, while forwarding logs to an external SIEM.

NetScaler Console’s Security Advisory workflow provides generic IOC checks when telemetry is enabled, and File Integrity Monitoring can flag unauthorized changes; Citrix cautions that automated checks may not identify every attacker technique.

Administrators should also treat CVE-2026-88778 separately by enabling Enhanced ISN Generation as directed, because the TCP configuration change is required in addition to software updates.

For 13.1 systems, running the show ns variable before upgrading is prudent: Citrix guidance cited by Cyber Security News warns that systems with configured variables may require 13.1-64.24 to avoid a reboot loop.

Cyber Security News previously alerted readers when researchers first reported two undisclosed NetScaler RCE zero-days, then covered Citrix’s confirmation, CVE assignments, and emergency fixes.

CISA has added two critical Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities catalog after evidence showed they were being actively exploited in attacks.

Its recent Citrix coverage also includes exploited CVE-2026-8452 and the 2025 CitrixBleed 2 campaign, reinforcing a familiar lesson: internet-facing edge appliances demand rapid asset discovery, forensic triage, patching, and continuous threat hunting.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post NCSC Urges UK organizations to Patch for Citrix NetScaler ADC and Gateway 0-Day Vulnerabilities appeared first on Cyber Security News.