Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway products, several intrusions in Finland
October 1, 2026 at 19:51
The National Cyber Security Centre Finland (NCSC-FI) has received reports of active exploitation of critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway products in Finland. Systems affected by the vulnerabilities must be updated to patched software versions without delay. Organisations must also check their environments for possible exploitation attempts and intrusions.
Varoituksen yhteenveto
Alert summary
- Alert: 1/2026
- Status: Active
- Yellow alert: The situation may require action or general caution by users or administrators
- Vulnerability severity: 7.0–9.5 (CVSS 4.0, high to critical)
- Affected products: Citrix NetScaler ADC and Citrix NetScaler Gateway
- Vulnerability identifiers: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778
- Impact: Remote code execution, authentication bypass, denial-of-service conditions and other unexpected system behaviour
- Remediation: Update the products immediately to versions patched by the vendor