Posts tagged with “citrix”

NetScaler CVE-2026-88772 zero-day tied to state hackers

Attackers exploited CVE-2026-88772, one of two recently disclosed Citrix NetScaler zero-days, in targeted intrusions starting in early September. The initial wave was likely the work of "advanced and suspected state-sponsored threat actors," according to Mandiant CTO Charles Carmakal.

Mandiant and Google Threat Intelligence Group (GTIG) know of dozens of affected organizations in North America and Europe. Carmakal said victims include organizations in the government, financial services, education, telecommunications, and legal and professional services sectors.

Two flaws, one confirmation

In the days before September 27, 2026, organizations around the world were notified of active attacks that appeared to involve an unknown flaw in Citrix NetScaler ADC and Gateway appliances. On that date, Citrix confirmed that two vulnerabilities had been exploited as zero-days: CVE-2026-88771 and CVE-2026-88772.

Read More


Citrix NetScaler CVE-2026-88771 now under mass attack

Attacks on unpatched Citrix NetScaler ADC and Gateway appliances have moved from a small number of targeted intrusions to broad, opportunistic exploitation across the internet. The change came after a root-cause analysis and a proof-of-concept (PoC) exploit for CVE-2026-88771 were published.

The flaw can be exploited remotely on unpatched devices running the default configuration. Researchers now say most exposed appliances have not yet been updated.

A zero-day confirmed by Citrix

Reports that attackers were exploiting an unknown NetScaler flaw began circulating late last week. Citrix confirmed them when it released a security advisory alongside patches for eight vulnerabilities rated critical or high risk.

Read More