NCSC Urges UK organizations to Patch for Citrix NetScaler ADC and Gateway 0-Day Vulnerabilities
Key Takeaways The UK’s National Cyber Security Centre (NCSC) has issued an urgent alert for organizations to patch critical Citrix NetScaler ADC and Gateway vulnerabilities. Two actively...
Key Takeaways
- The UK’s National Cyber Security Centre (NCSC) has issued an urgent alert for organizations to patch critical Citrix NetScaler ADC and Gateway vulnerabilities.
- Two actively exploited zero-day flaws, CVE-2023-4966 and CVE-2023-4967, affect multiple versions of these internet-facing appliances.
- Successful exploitation can lead to credential theft, persistent access, and lateral movement within internal networks due to the devices’ common placement at the network edge.
- While patches are available, organizations must also perform thorough forensic analysis to ensure systems haven’t already been compromised before restoration.
NCSC Urges Immediate Action on Exploited Citrix NetScaler Zero-Days
The National Cyber Security Centre (NCSC) in the UK has issued a critical warning to all domestic organizations, urging them to immediately apply security patches for two actively exploited zero-day vulnerabilities impacting Citrix NetScaler ADC and Gateway appliances. These flaws, identified as CVE-2023-4966 and CVE-2023-4967, pose significant risks to network security.
Table Of Content
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) previously added both vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling their active exploitation in the wild. This follows earlier reports from security researchers and subsequent confirmation by Citrix, who then released emergency fixes.
Understanding the Threat
Citrix NetScaler appliances are frequently deployed at the network perimeter, handling critical functions such as VPN connectivity, application delivery, and authentication traffic. This strategic placement means that a successful exploit can provide attackers with a highly valuable initial foothold. From this vantage point, adversaries can potentially steal credentials, establish persistent access, and move laterally into an organization’s internal network infrastructure.
The NCSC emphasizes that merely applying patches is insufficient to confirm the integrity of a system. Security teams must conduct comprehensive investigations to determine if an appliance was breached prior to patching.
Mitigation and Investigation Steps
Organizations should first implement temporary defensive measures, such as blocking external access via upstream firewalls, disabling vulnerable components, or restricting connections to only approved internal IP ranges. These steps can help contain potential threats while permanent fixes are applied.
Following these preliminary actions, forensic investigation is paramount. Defenders should preserve all relevant evidence and utilize Citrix’s published Indicators of Compromise (IOCs) to search for signs of compromise. Only after a thorough investigation and the installation of the appropriate fixed software build should services be restored, ensuring every node has been verified.
UK organizations that confirm a compromise are advised to report it through the government’s cyber-incident reporting service.
Ongoing monitoring is crucial even after patched systems are reintroduced. Organizations should continue to track Citrix’s security bulletins, conduct repeated threat hunts as new intelligence emerges, and validate that update levels remain consistent, especially across high-availability pairs.
Citrix NetScaler Console’s Security Advisory workflow, when telemetry is enabled, offers generic IOC checks. Additionally, File Integrity Monitoring (FIM) can help detect unauthorized changes. However, Citrix cautions that automated checks may not catch every sophisticated attacker technique.
Specific Patching Considerations
Administrators must address CVE-2026-88778 separately by enabling Enhanced ISN Generation as directed. This TCP configuration change is a mandatory step in addition to applying software updates.
For systems running version 13.1, it is prudent to execute “show ns variable” before initiating the upgrade process. Citrix guidance, as highlighted by Cyber Security News, indicates that systems with configured variables might require specific builds, such as 13.1-64.24, to prevent potential reboot loops during the update.
The recurring exploitation of internet-facing edge appliances, including past incidents like CVE-2026-8452 and the 2025 CitrixBleed 2 campaign, underscores the critical need for rapid asset discovery, forensic triage, timely patching, and continuous threat hunting.
What You Should Do
- Immediately apply the official security patches released by Citrix for NetScaler ADC and Gateway appliances.
- Prioritize temporary mitigation steps like restricting network access or disabling vulnerable components until patches are fully deployed.
- Conduct a comprehensive forensic investigation using Citrix’s published Indicators of Compromise (IOCs) to detect any pre-patch compromise.
- Monitor authentication logs, network activity, unexpected files, processes, configuration changes, and outbound connections, forwarding logs to an external SIEM.
- Ensure Enhanced ISN Generation is enabled for CVE-2026-88778 as a separate configuration step in addition to software updates.
- For NetScaler 13.1 systems, run “show ns variable” before upgrading and consult Citrix guidance to avoid reboot issues.
- Report any confirmed cyber incidents to the NCSC’s cyber-incident reporting service.
- Maintain continuous monitoring, repeat threat hunts, and validate consistent update levels across all high-availability pairs.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.