A technician monitors network security systems beside server racks in a hospital control room.
NetScaler zero-days lead a busy NHS tech roundup, and the patching sequence matters

Most of this morning's Digital Health briefing is NHS business: a supplier showcase, a procurement plan, an allergy app. The item that should get an IT admin's attention is the NetScaler alert. Two actively exploited Citrix NetScaler flaws are the kind of edge-device problem that turns a quiet Thursday into an incident bridge. The other items follow below, with the caveats each needs.

A technician monitors network security systems beside server racks in a hospital control room. The NetScaler zero-days: what is known​

Citrix's bulletin CTX697096, first published on 27 September 2026, covers eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are the actively exploited zero-days. Citrix says exploits of these two against unmitigated deployments have been observed. The UK's NCSC confirms the same: eight vulnerabilities, two of them actively exploited.

  • CVE-2026-88771 is an unauthenticated remote command-execution flaw caused by improper input validation. It affects all NetScaler ADC and Gateway deployments, including default configurations, and no extra feature has to be enabled. Its CVSS v4.0 base score is 9.5.
  • CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service. It applies where DTLS is enabled. A Gateway is vulnerable unless DTLS is explicitly disabled, and other virtual servers are vulnerable if they are configured with type DTLS. It also scores 9.5.
  • The other six are mostly denial-of-service, HTTP request smuggling, a policy bypass and TCP sequence-number prediction. ITPro lists them as CVE-2026-88773 through CVE-2026-88778 in the bulletin title.

Affected and fixed builds​

Citrix lists these as affected:

  • 14.1 before 14.1-73.37
  • 13.1 before 13.1-64.23
  • 14.1-FIPS before 14.1-73.37 FIPS
  • 13.1-FIPS and NDcPP before 13.1-37.279

Citrix says Secure Private Access Hybrid deployments that use NetScaler instances are also affected. The bulletin applies only to customer-managed appliances. Citrix-managed cloud services and Adaptive Authentication are updated by Cloud Software Group, so those customers have no patching to do.

One wrinkle comes from a third-party write-up, so treat it as secondary. Poppelgaard reports that if your NetScaler is a SAML Service Provider or Identity Provider, 14.1-73.37 and 13.1-64.24 are not enough, and you should upgrade again to 14.1-73.41 or 13.1-64.28. Check this against the live Citrix bulletin before you settle on a target build. Bulletins get revised.

Investigate first, then patch​

The NHS England alert, as reported by Digital Health, tells health organisations to do a compromise assessment before patching, upgrade to fixed releases, and report any evidence of compromise to the NHS England National CSOC. I couldn't retrieve the NHS alert itself, so this is Digital Health's account of it.

The wider guidance points the same way:

  • Patching is not cleanup. An upgrade replaces the vulnerable code, but it doesn't remove files an attacker already wrote or revoke credentials they already read. Qualys's Mayuresh Dani, quoted by ITPro, made the same point about webshells and suggested keeping affected devices under strict observation for at least 90 days.
  • Preserve evidence. NCSC-NL advised backing up the devices' memory and log files going back at least a month before installing updates. CISA urged organisations to check for compromise and preserve forensic evidence before updating where possible.
  • Contain, if you can. ITPro reports that the NCSC advises isolating affected systems and replacing them with a fully up-to-date system. The NCSC acknowledges this may cause an outage, for example by blocking access upstream or restricting it to your own IP range.
  • Use the vendor tooling. Citrix provides an IOC scan through NetScaler Console. It needs Console 14.1-73.36 or later with the telemetry channel enabled, and Citrix also recommends turning on File Integrity Monitoring. Citrix warns that the indicators might fail to identify real compromises.
  • Think about credentials. GBlock's write-up says Citrix's compromise guide tells companies to reset every account that authenticated through the Gateway and to rotate the LDAP and OAuth credentials stored on the appliance.

A practical checklist​

  1. Inventory every customer-managed NetScaler ADC and Gateway, including Secure Private Access Hybrid instances.
  2. Compare each build against the fixed releases above.
  3. Capture memory and at least 30 days of logs before changing anything.
  4. Run the IOC checks and hunt for compromise.
  5. Upgrade to the fixed build, or replace the appliance if you found evidence of compromise.
  6. Reset and rotate credentials that touched the appliance.
  7. Forward logs to an external system and keep watching.

On turning DTLS off, that only reduces exposure to CVE-2026-88772. It does nothing for CVE-2026-88771, so it isn't a real workaround.

Timing​

CISA added both flaws to its Known Exploited Vulnerabilities catalogue on 27 September, with a remediation due date of 30 September for covered federal agencies. Help Net Security's headline says the flaws were exploited globally for weeks before the fix. ITPro adds that the NCSC warned exploitation attempts could rise now that patches and technical details are out. Citrix has not published a root cause. A third-party analysis describes a log-poisoning path, but treat that as unofficial.

The bulletin also credits outside researchers, including the JPMorgan Chase XOR Team, for working with Citrix on the fixes.

The rest of the briefing​

Elevate showcase, Warrington (27 November)​

North Cheshire and Mersey NHS Foundation Trust was formed in April 2026 from the acute services of Warrington and Halton plus community services across more than 70 sites. It will host a supplier showcase at Thelwall House on the Warrington Hospital site. The organiser, Highland's Elevate team, says suppliers are limited to two per solution category. Replacing the electronic patient record is explicitly out of scope because the trust is running a procurement, but products that integrate cleanly with the EPR are welcome. The trust's priorities include cloud and SaaS security, endpoint security, and penetration testing. This is a showcase for suppliers, not a confirmed purchase. The event page lists a speaker session from £2,000 plus VAT.

Digital Primary Care Open Framework​

A planned procurement notice published on 6 October 2026 puts the estimated value at £838,749,369. It describes three lots:

  • Lot 1: foundation EPR, about £649.4m
  • Lot 2: clinical and operational support, about £135.3m
  • Lot 3: research and development, £54m

The notice says the procurement is intended to be issued in November 2026, subject to governance approvals. It expects go-live in Q3 2027. It describes itself as indicative and not a call to action.

Allergy Assist​

The Allergy Centre of Excellence service is app-based and paid. It covers children and young people aged 0 to 18 who live in the UK. Gold costs £75 a month and Platinum £150 a month, each with a minimum 12-month contract. Medication is billed separately. It is a private subscription, not an NHS-wide offering.

Medway's BIS Lens​

Medway NHS Foundation Trust is using BIS Lens, from BIS Consult, to pull fire-risk assessment data into dashboards for its Fire Safety Group. UKAuthority reports one early finding: a single estate-wide fix for cabling would be cheaper than several individual repairs. The alignment with HTM 05-03, HTM 05-01 and the "golden thread" principle is the trust's intent. It isn't an audited compliance outcome.

Interpretability paper​

The briefing dates "Leakage and Interpretability in Concept-Based Models" to 9 September 2026. The arXiv record shows a first submission on 18 April 2025 and a third version dated 24 March 2026, so the briefing's date doesn't match the record. The paper defines concepts-task leakage and interconcept leakage scores. It reports that these measures are strongly predictive of model behaviour under interventions and outperform existing alternatives. It does not say any specific NHS system is affected. For teams that buy or deploy clinical AI, the practical point is that leakage testing belongs in assurance.

DARC and macular atrophy​

This is an exploratory study of seven eyes, averaging 48.4 months of follow-up. The authors themselves call it a small preliminary study. It is a promising signal, not a basis for clinical practice.

Bottom line​

If you run NetScaler, work out your build today, preserve logs and memory, assess for compromise, then upgrade to the fixed build. Don't assume the patch alone closes the incident. Everything else in the briefing is useful context for health-IT watchers, but none of it is as time-sensitive as the NetScaler alert.

 

References

  1. Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com
  2. Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 support.citrix.com
  3. CVE-2026-88771 through CVE-2026-88778 and CVE-2026-88779, what you should know and how to fix your NetScaler ADC, NetScaler Gateway - Poppelgaard.com poppelgaard.com