Context
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway.
Key points to note and next actions
NCSC highlights a security bulletin published by Citrix, which details eight vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. Two of these, CVE-2026-88771 and CVE-2026-88772, have been confirmed as being actively exploited. The NCSC is working to understand the impact of these vulnerabilities on UK organisations. The vulnerabilities identified are:
- CVE-2026-88771: Improper input validation allowing an unauthenticated remote attacker to execute arbitrary commands.
- CVE-2026-88772: Improper restriction of operations within the bounds of a memory buffer, leading to remote code execution or denial of service.
- CVE-2026-88773: Inconsistent interpretation of HTTP requests (HTTP request/response smuggling), which may allow an attacker to manipulate or bypass security controls.
- CVE-2026-88774: Improper HTTP URL-based expression usage leading to a feature policy bypass.
- CVE-2026-88775: Memory overflow vulnerability that may result in unpredictable or erroneous behaviour, or denial of service.
- CVE-2026-88776: Memory overflow vulnerability that may result in unpredictable or erroneous behaviour, or denial of service.
- CVE-2026-88777: Memory overflow vulnerability that may result in unpredictable or erroneous behaviour, or denial of service.
- CVE-2026-88778: Predictable exact value vulnerability that may allow an attacker to influence integrity or availability.
Organisations using Citrix NetScaler ADC or Citrix NetScaler Gateway are affected, with the following supported versions of customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway being affected by the vulnerabilities:
- Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 before 14.1-73.37
- Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 before 13.1-64.23
- Citrix NetScaler ADC FIPS before 14.1-73.37 FIPS
- Citrix NetScaler ADC FIPS and NDcPP before 13.1-37.279
The notice provides information and highlights actions to follow in order to mitigate vulnerabilities.
