Cookie Consent by Free Privacy Policy Generator

NCSC urges UK organisations to patch actively exploited Citrix vulnerabilities

The National Cyber Security Centre has issued urgent guidance calling on UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. The NCSC reports that two of the vulnerabilities are being actively exploited in the wild. Citrix NetScaler products are widely deployed across UK enterprise networks to manage application delivery and remote access, making them high-value targets for attackers seeking initial access to corporate environments. The NCSC has not provided specific details about the nature of the exploitation activity but has made clear that organisations should treat this as a priority patching requirement.

Why this matters for UK organisations

Citrix infrastructure often sits at the perimeter of enterprise networks, handling authentication and access control for remote workers, third-party users and cloud applications. When vulnerabilities in these systems are actively exploited, the operational risk is immediate. Attackers may gain authenticated access to internal networks, bypass multi-factor authentication controls or move laterally to more sensitive systems. The fact that the NCSC has issued specific guidance rather than relying on vendor advisories alone suggests that UK organisations are being targeted or that exploitation is sufficiently widespread to warrant direct intervention. This is not theoretical risk; it is confirmed attacker activity affecting technology that many organisations depend on daily. For businesses running Citrix NetScaler, this represents a clear and present operational risk that requires prompt action.

What to review

UK businesses running Citrix NetScaler ADC or Gateway should confirm whether patches have been applied in line with NCSC guidance. It is worth checking whether these systems are included in routine vulnerability scanning and whether they are monitored for signs of exploitation or unusual authentication activity. Many organisations discover during incidents that perimeter appliances have unclear ownership between network, security and infrastructure teams, leading to delays in patching or monitoring. This is a good opportunity to confirm who is responsible for maintaining these systems, how quickly patches can be applied when required, and whether there is a clear escalation path if exploitation is suspected. Organisations should also review whether they have visibility into who is accessing these systems, from where, and whether access patterns are being monitored for anomalies. If Citrix systems are managed by third parties, it is worth confirming that those providers have applied the patches and are monitoring for exploitation activity.

Source: NCSC UK

News and blog posts
Today's brief reflects a pattern UK organisations will recognise: the need to...
The National Cyber Security Centre has issued urgent guidance calling on UK...
Google Threat Intelligence Group has published research examining vulnerability...
Cryptocurrency exchange Bitget has confirmed that attackers who stole $387.5...