WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH

Exploitation of security flaws affecting Citrix NetScaler ADC and Citrix NetScaler Gateway

A close-up of a chain link fence with padlocks securing it, symbolizing high security outdoors.
Illustrative photo.Photo by David McElwee on Pexels

What happened

The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited. Two of these, CVE-2026-88771 (the public catalogue number for a specific software flaw) and CVE-2026-88772, have been confirmed as being actively exploited .

The NCSC is working to understand the impact of these vulnerabilities on UK organisations. CVE-2026-88771: Improper input validation allowing an unauthenticated remote attacker to execute arbitrary commands.

CVE-2026-88772: Improper restriction of operations within the bounds of a memory buffer, leading to remote code execution (running programs on a machine from somewhere else) or denial of service. CVE-2026-88774: Improper HTTP URL-based expression usage leading to a feature policy bypass.

Organisations using Citrix NetScaler ADC or Citrix NetScaler Gateway on premises are affected. The NCSC strongly urges network defenders to follow these priority actions: Read the Citrix security bulletin and accompanying blog (includes IoCs) in full to determine if you have an affected system. For example, temporarily disable access to the service with upstream firewalls, disable the vulnerable component(s) or restrict access to only the organisation's IP range.

Sources & evidence