Live National Cyber Helpline · 0300 123 2040
Assured Cyber Protection Cyber & insurance briefing

News

Citrix NetScaler CVE-2026-88771 Exploited: Patch Now

By the Assured Cyber Protection team · Updated 2026 · Reviewed
Citrix NetScaler CVE-2026-88771 Exploited: Patch Now
Graphic by Assured Cyber Protection
Share this chartFacebookWhatsAppX

Two of this fortnight’s stories are about software small firms run without thinking about it: a remote access gateway and the website. Both have flaws attackers are already using. The data protection regulator also changed shape on 30 September, and DSIT published its yearly count of the UK cyber workforce.

Two new Citrix NetScaler flaws are being exploited

On 28 September the NCSC told UK organisations to act on eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are confirmed as being exploited. The first lets an unauthenticated attacker run commands on the device; the second is a memory bug that can lead to remote code execution. CISA had added both to its exploited list a day earlier, on 27 September, and gave US federal agencies until 30 September to deal with them.

The fixed versions are 14.1-73.37 and 13.1-64.23 for the standard builds, with separate FIPS and NDcPP builds listed by Citrix. The NCSC’s advice goes further than patching: isolate or replace an affected appliance where you can, check it against Citrix’s published indicators of compromise, then update and bring it back. That order matters, because a device that was compromised before the patch stays compromised after it.

This is the second NetScaler warning in five weeks; we covered the August flaw CISA set a 29 August deadline for. If your IT provider runs a NetScaler for remote access, ask them which version it is on today and whether they have checked it for compromise, not just whether it is patched. Under Cyber Essentials, a critical fix has to be applied within 14 days of release; our patch deadline calculator works out the date. The alert is on the NCSC website.

A WordPress core bug is under attack: check you are on 7.1.2

WordPress released 7.1.2 on 22 September as a security release for a single critical vulnerability. An unauthenticated attacker can, under certain server and theme conditions, make WordPress load a PHP file from outside the active theme folder, which can lead to remote code execution. Three days later, on 25 September, CISA added the flaw (CVE-2026-87902) to its Known Exploited Vulnerabilities catalogue, which means it has evidence of real attacks.

Most sites with automatic background updates will already have moved to 7.1.2. Sites where updates were switched off to stop a plugin breaking, or where an agency built the site and nobody has logged in since, are the ones at risk. Log in, check the version number in the dashboard footer, and update if it is lower. A hacked website that leaks customer details is a data breach like any other, and it is one of the scenarios cyber insurance is written to cover. Sources: the WordPress 7.1.2 release note and CISA’s catalogue.

The ICO is now the Information Commission

The change we flagged two weeks ago happened on 30 September. Under the Data (Use and Access) Act 2025 the regulator now has a board, the Information Commission Board, rather than a single Commissioner, and it has opened a new head office on Oxford Road in Manchester. The board appointed Maggie Carver as Deputy Chair; she will act as Chair while DCMS recruits a permanent one.

For a small business nothing about the day job changes. Breach reports, the data protection fee and complaints go through the same routes, and the regulator says its day-to-day work continues. A day later, on 1 October, it joined the National Cyber Resilience Centre Group’s National Ambassador programme, which links SMEs to the police-led regional Cyber Resilience Centres and their free or low-cost support. Its group director for cyber said many incidents it sees “stem from organisations not getting the basics right”. Read the governance announcement and the NCRCG announcement.

The UK cyber workforce is 145,900 people, and job adverts are up 7%

DSIT published its Cyber security skills in the UK labour market 2026 report on 29 September, covering the 2025 calendar year. About 145,900 people work in UK cyber security, up 2% on the year before. Postings for core cyber jobs rose 7% on 2024, and 53% of cyber firms expect to grow their headcount in 2026. The number of cyber security graduates reached 7,950, up 14% between the 2022/23 and 2023/24 academic years.

For a small firm buying security in, these numbers point one way: demand for skilled people is growing faster than the workforce, so managed services and consultancy are unlikely to get cheaper soon. If you are pricing a provider, our guide to managed cyber security services sets out what you should expect for the money. The report is on GOV.UK.

Also this fortnight

TikTok has dropped its appeal against the £12.7m fine the ICO issued in 2023 for misusing children’s data, so the penalty is final, the regulator said on 24 September. It also dropped a second appeal that had held up a separate investigation into how TikTok’s recommender systems use data from 13 to 17 year olds. Details are on the ICO website.

The Threat Brief

A calm, plain-English security update. Once a week.

New scams, breach lessons, and cyber insurance changes that affect UK businesses, explained without the jargon. No alarmism, no vendor spin.

Unsubscribe anytime. We never share your address.