Resources

Citrix NetScaler CTX697096 (CVE-2026-88771 and CVE-2026-88772) NCSC Alert Today, Cyber Security and Resilience Bill Report Stage Now Scheduled for Monday 26 October 2026, and the Kido Nursery and Cisco ArcaneDoor One-Year Anniversaries Fell Last Thursday: What UK Schools, Charities and SMBs Should Do in the Week Commencing 28 September 2026

Citrix has published NetScaler ADC and NetScaler Gateway security bulletin CTX697096 (27 September 2026), covering eight CVEs (CVE-2026-88771 through CVE-2026-88778). Two of them, CVE-2026-88771 (improper input validation, unauthenticated remote command execution, CVSS v4.0 9.5) and CVE-2026-88772 (memory overflow via DTLS leading to remote code execution or denial of service, CVSS v4.0 9.5) are confirmed as being actively exploited in the wild, with reports of exploitation for weeks before disclosure. Both were added to CISA's Known Exploited Vulnerabilities catalog on 27 September, and the NCSC published a full seven-step priority-action alert page on Monday 28 September. Affected releases: NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, with FIPS equivalents. In parallel, the Cyber Security and Resilience (Network and Information Systems) Bill has now been formally scheduled for Report stage in the Lords on Monday 26 October 2026, exactly four weeks and three days from today; the three amendment clusters flagged in ReadyToday post 38 (data-centre threshold symmetry, senior executive personal liability, statutory customer-communication window) will be tested on that day. Thursday 25 September 2026 was a double anniversary: one year since the Kido International nursery-chain ransomware incident was reported to Action Fraud (about 8,000 children's records exfiltrated by criminal group Radiant through a third-party image-sharing platform, 600,000 pound Bitcoin ransom demand not paid, two teenagers subsequently arrested); and one year since CISA issued Emergency Directive ED 25-03 on the Cisco ASA and Firepower Threat Defense ArcaneDoor zero-days (CVE-2025-20333 and CVE-2025-20362), a directive later updated in April 2026 to note an ArcaneDoor persistence mechanism that survives the September 2025 fixed builds. Three jobs for UK schools, charities and SMBs in the week commencing 28 September.

Key takeaways

  • Citrix published NetScaler ADC and NetScaler Gateway security bulletin CTX697096 on Sunday 27 September 2026 covering eight new CVEs (CVE-2026-88771 through CVE-2026-88778). Two are actively exploited in the wild and both carry a CVSS v4.0 score of 9.5: CVE-2026-88771 is an improper-input-validation defect allowing an unauthenticated remote attacker to run arbitrary commands on the appliance (the vulnerable path is present in every affected deployment, including the default configuration); CVE-2026-88772 is a memory overflow reachable via DTLS (which is on by default for VPN virtual servers) leading to remote code execution or denial of service. Both were added to CISA's Known Exploited Vulnerabilities catalog on 27 September 2026.
  • The NCSC has today (Monday 28 September 2026) published a dedicated alert page walking a seven-step priority-action list: read the Citrix bulletin and the accompanying TechZone blog for indicators of compromise; isolate affected systems if you can; fully investigate for evidence of compromise using the published IoCs; report through gov.uk/report-cyber if you find any; patch to 14.1-73.37 or 13.1-64.23 (or the FIPS equivalents); re-enable; continue to monitor and threat-hunt. The NCSC Early Warning service is free for UK organisations of any size and will notify you if your public IP space is being probed.
  • The Cyber Security and Resilience (Network and Information Systems) Bill's Report stage in the House of Lords has been formally scheduled for Monday 26 October 2026 - exactly four calendar weeks and three days from today, and the calendar peg forward-referenced in ReadyToday post 38. Three amendment clusters flagged at Committee stage (data-centre threshold symmetry, senior executive personal accountability at director level, and a statutory 24-hour customer-communication window) will be tested on the floor of the House that day. Government still expects Royal Assent in spring 2027 subject to parliamentary progress.
  • Thursday 25 September 2026 was a double calendar anniversary. One year since the Kido International nursery-chain ransomware incident was reported to Action Fraud: criminal group Radiant claimed to have exfiltrated personal data of about 8,000 children and staff (photographs, dates of birth, home addresses, parent contact details) via a third-party image-sharing platform, demanded a 600,000 pound Bitcoin ransom which was not paid, and publicly leaked two children's profiles before takedown; two teenagers were subsequently arrested. And one year since CISA issued Emergency Directive ED 25-03 on the Cisco ASA and Firepower Threat Defense ArcaneDoor zero-days (CVE-2025-20333 and CVE-2025-20362), a directive later updated in April 2026 to note an ArcaneDoor persistence mechanism that survives the September 2025 fixed builds.
  • Three jobs for the week commencing Monday 28 September 2026. First, on NetScaler: work through the NCSC's seven-step priority action list in order; if you have any NetScaler ADC or Gateway on a version earlier than 14.1-73.37 or 13.1-64.23 (or FIPS equivalents), isolate and investigate before patching. If you do not run NetScaler but you do run any other internet-exposed VPN concentrator (Fortinet, Palo Alto GlobalProtect, Cisco ASA/FTD, F5 BIG-IP APM), confirm a published patch SLA measured in days and enrol the appliance with the NCSC Early Warning service. Second, put Monday 26 October 2026 in the diary; reserve one hour that morning to skim the Marshalled List of Report-stage amendments once it is published on bills.parliament.uk. Third, on the double anniversary of 25 September: if you handle under-fives' data via any third-party platform, run a data-protection impact assessment on that supplier this week (MFA on staff and parent sides, Cyber Essentials Plus or equivalent, 24-hour breach-notification clause in the data-processor agreement); if you operate any Cisco ASA or Firepower Threat Defense appliance on your perimeter, run Cisco's published detection guide against it regardless of when you last patched.

Nineteen days after post #38 closed the Cyber Security and Resilience Bill's Grand Committee stage on Wednesday 9 September, and one day after Citrix's second NetScaler security bulletin of the season went live, this post lands three things for UK schools, multi-academy trusts, charities, SMBs, higher education and local authorities on Monday 28 September 2026. First, and the technical headline of this post: Citrix has published security bulletin CTX697096 covering eight new NetScaler ADC and NetScaler Gateway vulnerabilities, two of which — CVE-2026-88771 and CVE-2026-88772 — are being actively exploited in the wild, and the NCSC has today published a full alert page urging UK organisations to mitigate promptly. Second, the calendar peg: the Cyber Security and Resilience Bill's Report stage in the Lords has now been formally scheduled for Monday 26 October 2026, exactly one calendar month from today, and post #38's forward-reference has landed on a specific date. Third, the sub-anchor: Thursday 25 September 2026 was a double anniversary that touches every edge-appliance operator and every early-years or school-nursery operator in the UK — one year to the day since CISA issued Emergency Directive ED 25-03 on the Cisco ASA/FTD ArcaneDoor zero-days, and one year to the day since the Kido International nursery-chain ransomware incident was first reported to Action Fraud. The technical anchor and the sub-anchor are the same class of mistake — an internet-facing edge appliance or a third-party child-data platform, unpatched or under-monitored — the calendar peg is what makes an amendment on that class of mistake law by early 2027.

The technical headline: Citrix NetScaler CTX697096 (CVE-2026-88771 and CVE-2026-88772), NCSC alert 28 September 2026

Citrix's security bulletin CTX697096 was published on Sunday 27 September 2026 and covers eight vulnerabilities in NetScaler ADC and NetScaler Gateway numbered CVE-2026-88771 through CVE-2026-88778. Two of them are confirmed as being exploited in the wild before disclosure and are the reason CTX697096 is a stop-what-you-are-doing item on any UK team's Monday morning rota, not next Tuesday's patch window. CVE-2026-88771 is an improper-input-validation defect that allows an unauthenticated, remote attacker to execute arbitrary commands on the appliance — the full house: unauthenticated, remote, no user interaction, no elevated privileges required, and the vulnerable path is present in every affected deployment including the default configuration. It carries a CVSS v4.0 score of 9.5. CVE-2026-88772 is an improper-restriction-of-operations-within-the-bounds-of-a-memory-buffer defect (a classic memory overflow) leading to remote code execution or denial of service, reachable when DTLS is enabled — and DTLS is on by default for VPN virtual servers, so the precondition is met on most NetScaler Gateway deployments unless DTLS has been explicitly turned off. It also carries a CVSS v4.0 score of 9.5. The remaining six CVEs (88773 through 88778) cover HTTP request/response smuggling, a feature-policy bypass, three further memory-overflow denial-of-service variants and a predictable-exact-value defect; none are confirmed as being exploited in the wild at time of writing, but they ship in the same fixed builds and defenders should not skip them.

The affected releases are Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 before 14.1-73.37, and 13.1 before 13.1-64.23; the FIPS lines are also affected (14.1 FIPS before 14.1-73.37 FIPS, and 13.1 FIPS and NDcPP before 13.1-37.279). Note that these are new fixed builds — they are numerically higher than the 14.1-73.32 and 13.1-63.21 builds that closed post #37's CVE-2026-19490 story on 8 September. If your team patched to those August builds during the week of 8 September (Job One from post #37), the CTX697096 fixed builds are the next step and there is no version of the software before 14.1-73.37 or 13.1-64.23 that is safe on Monday 28 September 2026. Both CVE-2026-88771 and CVE-2026-88772 were added to CISA's Known Exploited Vulnerabilities catalog on 27 September 2026, the same day the Citrix bulletin was published; that is the loudest signal available to non-federal defenders (including UK schools, charities and SMBs) that a patch is not an optional item.

The NCSC has today (28 September 2026) published a dedicated alert page — "Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway" — that walks a seven-step priority action list: read the Citrix bulletin and its accompanying TechZone blog (which includes indicators of compromise) in full to determine whether you have an affected system; if possible, isolate the affected system and replace it with a new, fully up-to-date system, temporarily disabling access to the service with upstream firewalls if service outage is acceptable; fully investigate for evidence of compromise using the published IoCs; report any suspected compromise via gov.uk/report-cyber if you are in the UK; install the latest available updates; re-enable the affected system; and continue to monitor the bulletin and perform continuous threat hunting, using NetScaler Console File Integrity Monitoring where available. The NCSC's own vulnerability-management collection and preventing-lateral-movement guidance are linked from the alert, as is the free Early Warning service (which UK organisations of any size can sign up to and which will notify you if the NCSC sees your public IP space being probed).

Three points on the operational shape of this weekend's disclosure that non-federal UK defenders should read into the timing. First, Help Net Security has reported that both CVE-2026-88771 and CVE-2026-88772 were being exploited globally for weeks before the vendor disclosure on 27 September — that is, the appliances began being probed while post #38 was still writing up the August CVE-2026-19490 story, and Sunday's bulletin is the vendor-confirmation moment of a pre-existing intrusion campaign. Second, the fixed builds numbered 14.1-73.37 and 13.1-64.23 land only forty days after the fixed builds numbered 14.1-73.32 and 13.1-63.21 that closed the CVE-2026-19490 window on 19 August. Any UK NetScaler operator whose patch calendar assumed one edge-appliance patch cycle per calendar quarter is now short two cycles in six weeks. Third, the pattern is now recognisable across the whole class of internet-exposed VPN concentrator: FortiBleed on Fortinet in June and again in July with INC/Lynx follow-on, Palo Alto GlobalProtect referenced in the Qilin/Accesso post in late July, the Cisco ASA/FTD ArcaneDoor campaign anniversary that fell last Thursday, and now two NetScaler waves in the space of six weeks. If your organisation still terminates VPN sessions on an internet-exposed appliance without a strict published patch SLA measured in days not weeks, the class of mistake is by now a governance failure rather than an IT failure.

The calendar peg: Cyber Security and Resilience Bill Report stage now scheduled for Monday 26 October 2026

The Cyber Security and Resilience (Network and Information Systems) Bill closed its four-day Grand Committee stage on Wednesday 9 September (as written up in post #38), and the Lords' scheduling office has now formally listed Report stage for Monday 26 October 2026. That is exactly four calendar weeks and three days from today. Report stage is the substantive point at which the whole House considers Committee-stage amendments — the point at which the three amendment clusters that post #38 flagged (data-centre threshold symmetry, senior executive liability at director level, and a statutory customer-communication window) either move forward, are withdrawn, or force a government concession on the floor of the House. Between now and 26 October there will typically be at least one Marshalled List of amendments published on bills.parliament.uk, and a running commentary from the House of Lords Library, the Hansard Society Parliament Matters bulletin, and specialist trade press including UKAuthority and ComplianceHub.Wiki. Non-specialist readers should skim the Marshalled List once it is published (search "HL Bill 32" plus "Marshalled List" on bills.parliament.uk) rather than reading Hansard cold.

Two practical implications for the week commencing 28 September 2026. First, if your organisation is in scope of the Bill's expanded definition of "essential services" or of the new relevant digital services and managed service provider categories — most secondary schools, MATs, larger charities and mid-market SMBs whose customer base includes a regulated entity should assume they are — the 24-hour incident-reporting clock and the new senior executive personal-accountability tests will be law in some form by spring 2027. Government has already stated (in the June 2026 consultation response) that Royal Assent is expected in spring 2027 subject to parliamentary progress. Report stage on 26 October, Third Reading typically within one to three weeks after that, and Commons consideration of Lords amendments through November and December makes spring 2027 a plausible ceiling. Second, the practical planning window that opens today closes on 26 October: this is the last four-week period in which you can shape final amendments through consultation responses, meetings with sector bodies (NDNA for early years, ASCL for secondary school leadership, ACEVO for charity chief executives, Federation of Small Businesses for SMBs) and direct written submissions to relevant Peers. Post #38's Job One (read Committee-day-four Hansard) is now a settled document; post #39's replacement is to read the Marshalled List when it is published, and to compare each amendment against the three post-#38 clusters — data-centre threshold symmetry, senior executive liability, and the statutory customer-communication window.

The sub-anchor: 25 September 2026 was a double anniversary

Thursday 25 September 2026 was two separate calendar anniversaries that speak to two separate parts of ReadyToday's audience. On the same date one year earlier, the Kido International nursery chain reported a ransomware incident to Action Fraud in which the criminal group Radiant claimed to have exfiltrated personal data of about 8,000 children and staff — photographs, dates of birth, home addresses, parent contact details — via a third-party digital platform used to share children's images and developmental information with parents. The £600,000 Bitcoin ransom was not paid; two teenagers were later arrested; two children's data profiles were publicly leaked to the dark web before takedown; and the National Day Nurseries Association (NDNA) issued sector guidance shortly afterwards that specifically calls out third-party image-sharing platforms as a class of supplier that early-years settings, primary schools with nursery classes and MAT nursery arms should apply Cyber Essentials-flavoured due-diligence to. For any UK setting handling under-fives' data through a supplier's cloud, the Kido first anniversary is a natural moment to run the annual data-protection impact assessment on that supplier, cross-check whether MFA is enforced on both parent and staff sides of the platform, verify that the supplier holds either Cyber Essentials Plus or equivalent (ISO 27001, SOC 2 Type II), and confirm that your data-processor agreement contains a 24-hour breach-notification clause. The NCSC's training resources for school staff and the Cyber Governance for Boards resource, referenced in most previous ReadyToday posts, both apply directly.

On the same date one year earlier, CISA issued Emergency Directive ED 25-03 in response to the Cisco ASA and Firepower Threat Defense zero-days CVE-2025-20333 and CVE-2025-20362 exploited by the China-linked ArcaneDoor threat actor. That directive required U.S. federal agencies to identify and mitigate potentially compromised Cisco devices by 11:59 p.m. EDT on 26 September 2025. The story has not gone away: on 23 April 2026, CISA updated ED 25-03 to note that ArcaneDoor had developed a persistence mechanism that survived upgrading to the September 2025 fixed releases, and Cisco published a "Continued Attacks Against Cisco Firewalls" resource page and a companion advisory "Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense" earlier this year. For UK organisations, ED 25-03 is not a directive that binds them, but the underlying technical facts do bind anyone still running a Cisco ASA or FTD appliance on an internet-facing perimeter: the ArcaneDoor persistence mechanism can survive a nominal patch, so on the one-year anniversary a full boot-and-firmware verification against Cisco's published detection guide is the minimum defensible position. The parallel to the two NetScaler waves in six weeks is direct: the internet-exposed VPN concentrator is now the single most reliably exploited class of appliance across every major vendor, and the class of mistake — under-patched, under-monitored, no isolation plan — is the same on every one of them.

Three jobs for the week commencing Monday 28 September 2026

First, on your Citrix NetScaler estate: work through the NCSC's seven-step priority action list published today, in order. If you have any NetScaler ADC or Gateway appliance running a version earlier than 14.1-73.37 or 13.1-64.23 (or the FIPS equivalents), and you have not already isolated it, treat that as the first thing that happens on Monday morning. Read CTX697096 and the Citrix TechZone accompanying blog for indicators of compromise; investigate for evidence of compromise before you patch; patch to the fixed builds; monitor. If you are in the UK and find evidence of compromise, report through gov.uk/report-cyber. If you do not run NetScaler but you do run any other internet-exposed VPN concentrator (Fortinet, Palo Alto GlobalProtect, Cisco ASA/FTD, F5 BIG-IP APM — CVE-2026-94127 was disclosed by F5 on 22 September and is separately exploited as a zero-day), the class-of-mistake job is the same: confirm your published patch SLA is measured in days, confirm you have a documented isolation procedure, and confirm the appliance is enrolled with the NCSC Early Warning service.

Second, on the Cyber Security and Resilience Bill Report stage: put Monday 26 October 2026 in the diary and reserve one hour that morning to skim the Marshalled List once it is published. Between now and then, brief your board or trustees once (using the Cyber Governance Code of Practice and the ReadyToday post #38 summary) on the three amendment clusters that will matter for your organisation: data-centre threshold symmetry (does the Bill treat data-centre operators the same as other significant service providers?), senior executive personal accountability (a variant of the ISC2-flavoured director-level liability proposal), and a statutory 24-hour customer-communication window. If any of the three would materially change your operational exposure, brief your sector body (NDNA, ASCL, ACEVO or FSB depending on which part of the audience you sit in) this week.

Third, on the double anniversary of 25 September: if you are an early-years setting, a school with a nursery arm, or a MAT with any under-fives cohort, run one review this week of every third-party platform that holds photographs, developmental notes or parent contact details for under-fives. Check MFA on both the staff and parent sides; check that the supplier holds Cyber Essentials Plus or equivalent; check that the data-processor agreement contains a 24-hour breach-notification clause; check that you have a written procedure for what happens if the supplier reports a breach at 4 p.m. on a Friday. If you operate any Cisco ASA or Firepower Threat Defense appliance on your perimeter, run the Cisco published detection guide against it this week regardless of when you last patched, because the ArcaneDoor persistence mechanism survives a nominal upgrade.

What is not in this post

This is not a walk-through of the F5 BIG-IP APM CVE-2026-94127 zero-day disclosed on 22 September 2026 (CWE-122 heap-based buffer overflow, CVSS 9.8, actively exploited as a zero-day, affecting deployments where an APM access policy and an OAuth profile are attached to the same virtual server with APM in the OAuth Authorization Server role); it is referenced once above as a sister-story in the same class-of-mistake bracket. This is not a walk-through of the SonicWall SMA1000 CVE-2026-83548 and CVE-2026-83549 exploitation story, or the joint US/Japan/Australia/Germany advisory on the North Korean WaterPlum campaign that surfaced this month, or the SharePoint ToolShell follow-on from post #32. This is not a JLR update: the Reynolds/Unite/JLR meeting outcome was closed out in post #38; production has resumed and the running £1.9 billion Cyber Monitoring Centre modelling figure is unchanged from post #36. This is not a walk-through of the Beacon CRM/MAG client-side JavaScript story from post #35 or of the DfE ExfilSquad thread from post #33.

Where to get help

If you are unsure whether any of the seven NCSC priority actions apply to your organisation, or whether you have any NetScaler or Cisco ASA/FTD appliance on your perimeter at all, book a discovery call and we will walk your estate with you at no cost. ReadyToday is a UK-focused cyber-resilience practice serving schools, multi-academy trusts, charities and SMBs; every recommendation in this post is either free or maps to a Cyber Essentials-priced control.

Written by Boris Didov