Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Vendors and products
- Citrix
- Reported by
- 1 outlet
Get our latest cybersecurity news first on Google.
Attackers remained undetected for more than three weeks as they exploited a critical zero-day vulnerability affecting Citrix NetScaler appliances en masse.
The earliest known instance of CVE-2026-88772 exploitation occurred Sept. 3, Mandiant researchers told CyberScoop Tuesday.
The besieged security vendor and researchers didn’t confirm the attacks until late last week. By then, Mandiant says, organizations in North America and Europe spanning the government, financial services, education, telecom, legal and professional services sectors were already likely compromised.
“We are aware of dozens of impacted organizations,” Charles Carmakal, chief technology officer at Mandiant Consulting, wrote in a LinkedIn post. He attributed the attacks to “advanced and suspected state-sponsored threat actors.”
The three-week gap — at minimum — between initial exploitation and confirmed in-the-wild attacks gave attackers a significant advantage.
Mandiant warned that the gap could be even wider. “We are still responding to active intrusions, and new evidence may change our understanding of the campaign timeline,” researchers who published a threat intelligence report on the attacks Tuesday told CyberScoop in an email.
The incident response firm’s analysis on the latest zero-day attack spree targeting Citrix customers underscores the multi-layered mess network defenders have been responding to since Saturday.
The zero-day exploits in Mandiant’s report only cover half of the problem. Attackers have also exploited a second Citrix NetScaler zero-day — CVE-2026-88771 — since at least Sept. 24, according to GreyNoise, but researchers said that campaign likely started earlier as well.
It’s unclear to what extent the pair of zero-days are linked. But, nearly two days after the first unconfirmed rumors of the attacks surfaced, Citrix disclosed both of the actively exploited defects in a security advisory Sunday, releasing patches for them and six additional vulnerabilities.
Mandiant researchers uncovered multiple novel tools and tactics attackers used to exploit CVE-2026-88772, gain privileged access to compromised environments, hop around the network and steal sensitive data. A threat actor in one observed intrusion routed traffic through novel tunneler malware to “manually conduct internal reconnaissance and credential theft,” researchers wrote.
Researchers at watchTowr also published technical analysis of CVE-2026-88782 Tuesday.
The attacks from multiple fronts, involving two zero-days, reflect an alarming and sustained pattern of malicious activity targeting so-called edge devices, such as virtual private network gateways and firewalls.
Vulnerabilities in these devices accounted for 48% of the enterprise-related zero-days last year, according to Google Threat Intelligence Group.
“Our previous research corroborates that both cyber espionage and financially motivated threat actors prioritize exploiting vulnerabilities in edge devices and security appliances,” Mandiant researchers wrote in response to questions on their report.
“Because most edge devices do not support endpoint detection and response (EDR) monitoring, targeting them, particularly through exploiting zero-day vulnerabilities, provides threat actors with an infection vector that is difficult to detect and prevent, and the opportunity to scale a campaign as long as the exploit remains undiscovered,” the researchers added.
Carmakal, in his LinkedIn post, warned that Mandiant expects “broad and opportunistic exploitation” of both of the Citrix NetScaler zero-days by a variety of threat actors in the near term.
Latest Podcasts
Government
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
As AI world debates security, NVIDIA releases open source tools for agents
ShinyHunters trades financial extortion for a reckless war of ego with the FBI
Supreme Court permits states to use SAVE database for citizenship checks
Technology
New bill would create federal investigative body for AI-driven hacks
CISA outlines improvement plan for CVE program
OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems
Citing China, President Trump doubles down on hands-off approach to AI regulation
Threats
Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
Ryuk ransomware operator sentenced to 2 years in prison
Policy
Originally published by CyberScoop. © CyberScoop. Written by Matt Kapko.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-29 21:30 UTC
Related stories
- US Air Force members given over 6 years in prison for cyber theft of more than $2 million
The Record · 2026-09-29
- [Control systems] Hitachi security advisory (AV26-975)
Canadian Centre for Cyber Security · 2026-09-29
- TeamViewer security advisory (AV26-977)
Canadian Centre for Cyber Security · 2026-09-29
- Mozilla security advisory (AV26-976)
Canadian Centre for Cyber Security · 2026-09-29