cybelangel.com Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland
Article Content
- •Critical vulnerabilities CVE-2026-88771 and CVE-2026-88772 are actively exploited.
- •Exploitation began before patches were released on September 27, 2026.
- •NCSC-FI identified hundreds of vulnerable NetScaler instances in Finland.
The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without authentication and potentially launch denial-of-service attacks. Exploitation began before Citrix released patches on September 27, 2026, leading to concerns that attackers may have established persistent access to affected systems. The NCSC-FI has identified hundreds of vulnerable NetScaler instances in Finland and has contacted their administrators to recommend immediate updates and thorough investigations for signs of compromise. Organizations are urged to review logs, check for unauthorized changes, and change administrative passwords if a breach is suspected. The vulnerabilities affect versions 13.1 and 14.1 of NetScaler products, including their FIPS and NDcPP versions released prior to the patches.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track Citrix and CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of NetScaler are affected?
What should organizations do immediately?
How are these vulnerabilities being exploited?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…