The National Cyber Security Centre has issued fresh guidance urging UK organisations to take immediate action on two vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway — the appliances many businesses use to run VPNs and single sign-on. The more serious of the two, tracked as CVE-2026-3055, is a critical, unauthenticated memory-overread flaw that’s already being actively exploited in the wild. If your business — or your IT provider — runs a NetScaler appliance for remote access, this is not a “get to it next month” issue.

The flaw lets an attacker send a malformed request to the login page and read back kilobytes of leftover memory from the device, including session tokens, login credentials, and authentication data — all without needing to log in first. Combined with a second, lower-severity race condition bug (CVE-2026-4368), it gives attackers a realistic path to hijacking active sessions on internet-facing gateways. Security researchers have already nicknamed it “CitrixBleed 3,” a nod to a previous NetScaler vulnerability that caused widespread damage when organisations were slow to patch.

Why this matters even if you’ve never heard of NetScaler

Most small businesses don’t run these appliances directly — but plenty use an IT support provider, managed service provider, or bigger supplier who does. NetScaler sits at the edge of a network, handling remote access and single sign-on for staff working outside the office, which makes it an attractive target: compromise the gateway, and you potentially get a foothold into everything behind it. If any part of your remote access, VPN, or supplier’s infrastructure runs through Citrix, this is worth a direct question to whoever manages it, today.

What to actually do about it

Citrix has published patched builds — 14.1-66.59, 13.1-62.23, and the FIPS/NDcPP 13.1-37.262 release — and the fix is straightforward to apply for anyone already managing the appliance. The practical steps for an SME are:

Ask your IT provider directly whether you run NetScaler ADC or Gateway anywhere in your infrastructure, and if so, whether it’s been patched to one of the versions above. Don’t assume “we’ll get to it” is good enough — active exploitation means the window between disclosure and attack is already closed for anyone who hasn’t moved. If you use a third-party supplier for remote access or VPN services, ask them the same question; a compromise on their side can just as easily expose your data.

For businesses without an in-house IT function, this is exactly the kind of gap a managed support arrangement is meant to catch before it becomes a headline. CoolCoding can review whether any of your infrastructure or suppliers touch affected Citrix products and get patching sorted without you needing to become a vulnerability-tracking expert overnight.

The bigger pattern

This is the third major NCSC alert about internet-facing network appliances in as many months — following warnings on Fortinet firewalls and VPN gateways, and ongoing hostile-state activity targeting UK supply chains. The common thread is clear: the software sitting at the edge of your network, handling remote access and authentication, is where attackers are concentrating effort right now, precisely because it’s often the least-monitored, least-frequently-patched part of a business’s setup. Building a habit of checking these gateway systems on a regular cycle — not just when a headline forces the question — closes off a disproportionate share of realistic attack paths.

The takeaway

If you or your IT provider run Citrix NetScaler ADC or Gateway, confirm today whether it’s patched to a safe build. If you don’t know, that’s the question to ask this afternoon — active exploitation means every day unpatched is a day of real exposure, not theoretical risk.