The UK National Cyber Security Centre (NCSC) has issued a critical advisory urging organizations to urgently address several vulnerabilities impacting Citrix NetScaler ADC and Gateway appliances. The call to action follows the discovery of two critical zero-day vulnerabilities, designated CVE-2026-88771 and CVE-2026-88772, which are actively being exploited by attackers.
Understanding the Citrix NetScaler Vulnerabilities
According to Citrix’s CTX697096 bulletin, the two most severe vulnerabilities possess a CVSS 4.0 score of 9.5. The first, CVE-2026-88771, is an improper input-validation flaw that allows remote attackers to execute arbitrary commands without authentication. This vulnerability exists across all vulnerable configurations of NetScaler, including those with default settings.
The second flaw, CVE-2026-88772, involves a memory overflow issue that can lead to either remote code execution or denial of service when DTLS is enabled, a feature that is typically active in VPN virtual servers by default.
Additional Security Weaknesses and Mitigations
The security update also addresses six further vulnerabilities that span various features of the affected systems. These include CVE-2026-88773, which allows HTTP request smuggling, and CVE-2026-88774 that can bypass certain policy controls. Memory-overflow vulnerabilities like CVE-2026-88775, CVE-2026-88776, and CVE-2026-88777 impact different server configurations, while CVE-2026-88778 poses risks with TCP sequence number prediction.
Organizations are advised to upgrade Citrix-managed cloud services and adaptive authentication systems, as well as to implement specific TCP configuration changes to address these vulnerabilities thoroughly.
Recommended Actions for Organizations
The NCSC emphasizes the need for organizations to consult Citrix’s detailed advisory and blog post to better understand the risks and necessary actions. Affected systems should be isolated if possible, and defenses should include blocking access via firewalls and restricting network connections to trusted IP addresses.
To ensure systems are not compromised, defenders are encouraged to preserve logs for forensic analysis, apply the latest patches, and verify all network nodes before restoring full service. It’s crucial for UK entities to report any confirmed breaches through the government’s cyber-incident reporting service.
Ensuring Long-term Security
Given the strategic position of NetScaler appliances in network architecture, successful exploitation could enable attackers to steal credentials and move laterally within networks. Therefore, post-patch monitoring, continuous threat intelligence updates, and regular security audits are essential.
Security teams should employ tools like File Integrity Monitoring to detect unauthorized changes and ensure logs are sent to an external SIEM for comprehensive analysis. In addition, specific vulnerabilities like CVE-2026-88778 require separate TCP configuration changes beyond just applying software updates.
Finally, Citrix users are advised to remain vigilant and proactive, continually monitoring for new threats and ensuring that all updates are applied across high-availability setups.
