Citrix NetScaler vulnerabilities exploited in Finland
The National Cyber Security Centre Finland (NCSC-FI) has issued an alert about several critical vulnerabilities in Citrix NetScaler ADC and Gateway products that are also being actively exploited in Finland. The vulnerabilities may allow attackers to execute remote code without authentication, launch denial-of-service attacks and carry out other malicious activity on affected systems. The NCSC-FI recommends that organisations update vulnerable systems immediately and check their environments for signs of exploitation.
Intrusions occurred even before Citrix released security updates on 27 September 2026. Updating the software alone may therefore not be enough. Organisations must also investigate whether their systems were compromised before the updates were installed.
According to information received by the NCSC-FI, the vulnerabilities were exploited in Finland before the security updates were released. Users of internet-facing NetScaler systems should therefore assume that their systems may have been exposed to attacks. Updating the software alone may not be enough, as an attacker may have established a persistent foothold in the environment before the patches were installed.
The NCSC-FI has identified hundreds of NetScaler instances in Finland and contacted their administrators. The NCSC-FI stresses the importance of both rapid patching and follow-up investigations, as intrusions carried out by exploiting zero-day vulnerabilities may go undetected without separate checks.
The NCSC-FI recommends that organisations update all vulnerable NetScaler ADC and Gateway systems to patched versions, review logs and administrative changes and investigate any signs of attacks or intrusions. Organisations should also check user accounts created on the systems, scheduled tasks, services and other changes that could enable persistence. If a compromise is suspected, organisations should change the passwords for administrative accounts and assess whether the system has been used as a route into other systems on the internal network.
The vulnerability affects versions 13.1 and 14.1 of NetScaler ADC and Gateway products as well as their FIPS and NDcPP versions released before the vendor's patched versions. The NCSC-FI asks organisations to report any observed exploitation, intrusions and attack attempts to help maintain situational awareness and support the protection of other organisations.