# NCSC warns of exploited NetScaler flaws

Published: 2026-09-28 · Severity: severe · Sectors: technology, infrastructure, government-national
Canonical: https://vorant.io/reports/37aae86e-ef4b-5126-aa34-da4f10875932/ncsc-warns-of-exploited-netscaler-flaws

> NCSC urges urgent patching of eight Citrix NetScaler ADC/Gateway vulnerabilities, two of which are actively exploited in the wild.

The NCSC has issued an advisory highlighting eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, following Citrix's own security bulletin. Two of these, CVE-2026-88771 (unauthenticated remote command execution via improper input validation) and CVE-2026-88772 (memory buffer bounds issue leading to RCE or DoS), have been confirmed as actively exploited. The remaining six vulnerabilities include HTTP request smuggling, a URL-based feature policy bypass, multiple memory overflow issues causing unpredictable behaviour or DoS, and a predictable value flaw affecting integrity or availability.

Affected products are customer-managed, on-premises deployments of NetScaler ADC and Gateway versions prior to 14.1-73.37 and 13.1-64.23, along with FIPS and NDcPP variants below specified patch levels. The NCSC is still assessing impact on UK organisations but strongly recommends immediate action given active exploitation of two critical flaws.

Defenders should read the Citrix bulletin and blog in full (which includes IoCs), isolate affected systems where possible, investigate for compromise using published indicators, and apply the latest patches without delay. NetScaler Console File Integrity Monitoring can help detect unauthorised file changes. UK organisations that identify compromise are urged to report to the NCSC and Citrix, and to continue monitoring the Citrix bulletin for updates while performing ongoing threat hunting.

## Mentioned in this report

- Vulnerabilities: CVE-2026-88771 (KEV), CVE-2026-88772 (KEV), CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778

Source reporting: https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/37aae86e-ef4b-5126-aa34-da4f10875932/ncsc-warns-of-exploited-netscaler-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
