NCSC warns of exploited NetScaler flaws
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
NCSC urges urgent patching of eight Citrix NetScaler ADC/Gateway vulnerabilities, two of which are actively exploited in the wild.
The NCSC has issued an advisory highlighting eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, following Citrix's own security bulletin. Two of these, CVE-2026-88771 (unauthenticated remote command execution via improper input validation) and CVE-2026-88772 (memory buffer bounds issue leading to RCE or DoS), have been confirmed as actively exploited. The remaining six vulnerabilities include HTTP request smuggling, a URL-based feature policy bypass, multiple memory overflow issues causing unpredictable behaviour or DoS, and a predictable value flaw affecting integrity or availability.
Affected products are customer-managed, on-premises deployments of NetScaler ADC and Gateway versions prior to 14.1-73.37 and 13.1-64.23, along with FIPS and NDcPP variants below specified patch levels. The NCSC is still assessing impact on UK organisations but strongly recommends immediate action given active exploitation of two critical flaws.
Defenders should read the Citrix bulletin and blog in full (which includes IoCs), isolate affected systems where possible, investigate for compromise using published indicators, and apply the latest patches without delay. NetScaler Console File Integrity Monitoring can help detect unauthorised file changes. UK organisations that identify compromise are urged to report to the NCSC and Citrix, and to continue monitoring the Citrix bulletin for updates while performing ongoing threat hunting.
Mentioned in this report
Source reporting: https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,126 reports from 154 sources, 2,670 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs