Jessica Entwistle
September 30 2026
The National Cyber Security Centre has issued an urgent advisory calling on UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway appliances, two of which are being actively exploited in the wild. The NCSC published the alert on 28 September 2026, naming CVE-2026-88772 as a critical memory overflow flaw in the DTLS protocol handling that allows pre-authentication remote code execution. Mandiant researchers have confirmed that advanced and suspected state-sponsored threat groups exploited this vulnerability for at least three weeks before detection, impacting dozens of organisations. The NCSC's advisory emphasises that NetScaler appliances are widely deployed across UK enterprise networks for application delivery and secure remote access, making them high-value targets for attackers seeking persistent access to corporate environments.
NetScaler devices sit at the perimeter of many organisations, handling authentication, load balancing and VPN access for remote workers. A compromise at this level can provide attackers with deep visibility into internal networks, the ability to intercept credentials, and a foothold for lateral movement. The fact that exploitation went undetected for weeks highlights how difficult it can be to spot malicious activity on infrastructure appliances without robust logging, monitoring and threat detection capabilities. Organisations that have not yet applied Citrix's patches or implemented the recommended mitigations are exposed to a known and actively exploited attack path. The operational risk is significant: perimeter devices are often trusted implicitly, and a compromise can undermine the security of everything behind them. This is particularly concerning for organisations that rely on NetScaler for remote access, as attackers with control of these devices can intercept authentication traffic, harvest credentials and move laterally into internal systems.
UK businesses using Citrix NetScaler should review patching status immediately and ensure that perimeter devices are included in routine vulnerability management processes. If patching cannot be completed quickly, organisations should implement the NCSC's recommended mitigations and review logs for signs of compromise. It is also worth considering whether perimeter infrastructure is adequately monitored and whether logging is configured to detect unusual access patterns, configuration changes or anomalous traffic. Organisations should confirm that responsibility for patching and monitoring perimeter devices is clearly assigned and that these systems are included in regular security reviews. This incident is a reminder that visibility into how perimeter infrastructure is being accessed and by whom is a fundamental security control, and that delays in patching high-risk devices can create significant operational exposure.
Source: NCSC UK