Cookie Consent by Free Privacy Policy Generator

NCSC urges UK organisations to patch actively exploited Citrix NetScaler vulnerabilities

The National Cyber Security Centre has issued urgent guidance calling on UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products. The NCSC reports that two of the eight newly disclosed vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being actively exploited in the wild. Both are critical zero-day flaws that can independently enable remote code execution. CISA in the United States has added both vulnerabilities to its Known Exploited Vulnerabilities catalogue, and the NCSC has confirmed it has received reports of active exploitation targeting these products. Citrix has released patches and mitigation guidance for affected versions.

Why this matters for UK organisations

Citrix NetScaler ADC and Gateway are widely deployed across UK enterprise and public sector networks to manage application delivery and secure remote access. These products sit at the network edge, making them high-value targets for attackers seeking initial access to corporate environments. The fact that exploitation is already underway means organisations running affected versions face immediate risk. The vulnerabilities affect multiple product versions, and for many organisations, NetScaler appliances are managed by infrastructure or network teams rather than security teams directly, which can sometimes delay awareness and response when vulnerabilities are disclosed. The NCSC's decision to issue specific guidance for UK organisations reflects the operational significance of these products and the urgency of the threat.

What to review

UK organisations running Citrix NetScaler ADC or Gateway should verify patch status immediately and ensure that responsibility for applying updates to these appliances is clearly assigned and tracked. If patching cannot be completed quickly, organisations should review and apply the vendor's recommended mitigations and consider whether additional monitoring or access restrictions can reduce exposure while patches are deployed. This is also an opportunity to confirm that processes are in place to ensure that security advisories for edge infrastructure products reach the teams responsible for managing them, and that those teams have the authority and resources to respond quickly when active exploitation is confirmed. Organisations should also review whether NetScaler appliances are included in regular vulnerability scanning and patch management processes, and whether logging and monitoring are in place to detect signs of compromise or unusual activity on these systems.

Source: NCSC UK

News and blog posts
The National Cyber Security Centre has issued urgent guidance calling on UK...
Microsoft has published threat intelligence warning that a threat actor it...
OpenAI has paused the planned October release of its next-generation AI model,...
The Register reports that OpenAI has confirmed its AI agents accessed four...