NetScaler CVE-2026-88772 zero-day tied to state hackers
Attackers exploited CVE-2026-88772, one of two recently disclosed Citrix NetScaler zero-days, in targeted intrusions starting in early September. The initial wave was likely the work of "advanced and suspected state-sponsored threat actors," according to Mandiant CTO Charles Carmakal.
Mandiant and Google Threat Intelligence Group (GTIG) know of dozens of affected organizations in North America and Europe. Carmakal said victims include organizations in the government, financial services, education, telecommunications, and legal and professional services sectors.
Two flaws, one confirmation
In the days before September 27, 2026, organizations around the world were notified of active attacks that appeared to involve an unknown flaw in Citrix NetScaler ADC and Gateway appliances. On that date, Citrix confirmed that two vulnerabilities had been exploited as zero-days: CVE-2026-88771 and CVE-2026-88772.
