Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Suspected state-sponsored actors mass-exploited Citrix NetScaler zero-day CVE-2026-88772 undetected for over three weeks, hitting dozens of organizations.
Mandiant reports earliest known exploitation of Citrix NetScaler zero-day CVE-2026-88772 occurred Sept. 3, with dozens of organizations in North America and Europe across government, financial services, education, telecom, legal and professional services compromised before attacks were confirmed late last week. A second zero-day, CVE-2026-88771, has been exploited since at least Sept. 24 per GreyNoise. Citrix patched both flaws plus six additional vulnerabilities Sunday; Mandiant expects broad, opportunistic exploitation of both zero-days by varied threat actors.
95