THE UK National Cyber Security Centre (NCSC) is urging organisations to urgently address eight vulnerabilities affecting on-premises Citrix NetScaler ADC and Citrix NetScaler Gateway. Citrix has confirmed that two flaws, CVE-2026-88771 and CVE-2026-88772, are being actively exploited.
CVE-2026-88771 allows an unauthenticated remote attacker to execute arbitrary commands through improper input validation, while CVE-2026-88772 can enable remote code execution or denial of service through operations exceeding a memory buffer. The other vulnerabilities involve HTTP request smuggling, policy bypass, memory overflows and a predictable-value weakness that could affect integrity or availability.
Affected customer-managed versions include NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, plus specified FIPS and NDcPP releases. The NCSC says it is assessing the impact on UK organisations and advises defenders to consult Citrix’s security bulletin and accompanying blog, which include indicators of compromise.
Where possible, organisations should isolate affected systems—potentially causing an outage—or restrict access, investigate for compromise, install the latest available updates and then restore services. UK organisations that believe they have been compromised should report the incident through the government’s cyber reporting service and to Citrix. The NCSC also recommends continued monitoring and threat hunting after remediation.