Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway products, several intrusions in Finland | Traficom

Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway products, several intrusions in Finland | Traficom

By Traficom
Publication Date: 2026-10-01 00:00:00

What do we know about the vulnerabilities?

Citrix released several critical security fixes for NetScaler ADC and NetScaler Gateway products on 27 September 2026. The vulnerabilities include flaws related to remote code execution, HTTP request smuggling, memory corruption and the bypassing of security mechanisms. Organisations of different sizes use the products to provide secure remote access for their employees.

The most severe vulnerability, CVE-2026-88771, may allow commands to be executed on the target system without authentication. Several of the other vulnerabilities may lead to denial-of-service conditions, system instability or other attacker-controlled activity.

The NCSC-FI has received reports of exploitation of the vulnerabilities, meaning intrusions in Finland. Exploitation began before Citrix released the patches. Organisations should assume that internet-facing NetScaler systems may have been exposed to attack attempts. The intrusions in Finland underline the need for…