The UK National Cyber Security Centre (NCSC) has urged organisations to act quickly after Citrix disclosed eight security vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway appliances. According to the agency, two of the flaws are being actively exploited.
The actively exploited issues are tracked as CVE-2026-88771 and CVE-2026-88772. The first is an input-validation flaw that could allow an unauthenticated remote attacker to run arbitrary commands. The second is a memory-boundary vulnerability that may result in remote code execution or denial-of-service conditions.
The remaining vulnerabilities include HTTP request smuggling, a policy-bypass issue related to URL-based expressions, several memory-overflow flaws, and a predictable-value weakness that could affect system integrity or availability.
Affected versions
The advisory applies to on-premises deployments of supported NetScaler products. Affected releases include NetScaler ADC and Gateway 14.1 versions earlier than 14.1-73.37, and 13.1 versions earlier than 13.1-64.23. NetScaler ADC FIPS versions before 14.1-73.37 FIPS and FIPS/NDcPP versions before 13.1-37.279 are also listed as affected.
Recommended response
The NCSC recommends that administrators review Citrix’s security bulletin and related technical guidance, including published indicators of compromise, to establish whether their environments are exposed or have been breached.
- Where practical, temporarily isolate affected appliances or limit access using firewall rules and IP restrictions.
- Investigate systems for evidence of compromise using vendor-provided indicators.
- Apply the latest Citrix updates after completing the initial assessment.
- Restore services only after appropriate mitigations and updates are in place.
- Continue threat-hunting and monitor Citrix guidance for further developments.
Organisations that identify a compromise should follow their incident-response procedures. UK organisations can report incidents to the NCSC and may use the agency’s Early Warning service for notifications of potential threats affecting their networks. The agency also pointed defenders to its guidance on vulnerability management and reducing opportunities for lateral movement.
