Skip to content
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland

Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •Critical vulnerabilities CVE-2026-88771 and CVE-2026-88772 are actively exploited.
  • •Exploitation began before patches were released on September 27, 2026.
  • •NCSC-FI identified hundreds of vulnerable NetScaler instances in Finland.

The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without authentication and potentially launch denial-of-service attacks. Exploitation began before Citrix released patches on September 27, 2026, leading to concerns that attackers may have established persistent access to affected systems. The NCSC-FI has identified hundreds of vulnerable NetScaler instances in Finland and has contacted their administrators to recommend immediate updates and thorough investigations for signs of compromise. Organizations are urged to review logs, check for unauthorized changes, and change administrative passwords if a breach is suspected. The vulnerabilities affect versions 13.1 and 14.1 of NetScaler products, including their FIPS and NDcPP versions released prior to the patches.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-26
Public warning issued about NetScaler vulnerabilities
Researchers warned of active exploitation of CVE-2026-88771 and CVE-2026-88772 before vendor confirmation.
CybelAngel
2026-09-27
Citrix releases patches for vulnerabilities
Citrix published security bulletin CTX697096 addressing CVE-2026-88771 and CVE-2026-88772, confirming active exploitation.
MyITForum
2026-09-27
CVE-2026-88772 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88771 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-01
NCSC-FI issues alert on exploitation in Finland
The NCSC-FI alerted organizations about the ongoing exploitation of Citrix NetScaler vulnerabilities.
Kyberturvallisuuskeskus.Fi

More articles in this cluster (7)

Following this threat?

Track Citrix and CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of NetScaler are affected?
Versions 13.1 and 14.1 of NetScaler ADC and Gateway products, including FIPS and NDcPP versions released before the patches.
What should organizations do immediately?
Organizations should update their NetScaler systems immediately and investigate for any signs of compromise.
How are these vulnerabilities being exploited?
Attackers can exploit these vulnerabilities to execute remote code without authentication and potentially launch denial-of-service attacks.