Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Suspected state-sponsored actors mass-exploited Citrix NetScaler zero-day CVE-2026-88772 undetected for over three weeks, hitting dozens of organizations.
Mandiant reports earliest known exploitation of Citrix NetScaler zero-day CVE-2026-88772 occurred Sept. 3, with dozens of organizations in North America and Europe across government, financial services, education, telecom, legal and professional services compromised before attacks were confirmed late last week. A second zero-day, CVE-2026-88771, has been exploited since at least Sept. 24 per GreyNoise. Citrix patched both flaws plus six additional vulnerabilities Sunday; Mandiant expects broad, opportunistic exploitation of both zero-days by varied threat actors.
- CVE-2026-88772 exploited since at least Sept. 3, undetected for three-plus weeks
- Dozens of government, finance, telecom, education and legal organizations impacted
- Attributed to advanced, suspected state-sponsored threat actors
- Second zero-day CVE-2026-88771 exploited since at least Sept. 24
- Attackers used novel tunneler malware for internal reconnaissance and credential theft
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
Full article749 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Mandiant researchers said dozens of organizations have been impacted by attacks attributed to advanced and suspected state-sponsored threat groups. They expect more attacks to come.
Attackers remained undetected for more than three weeks as they exploited a critical zero-day vulnerability affecting Citrix NetScaler appliances en masse.
The earliest known instance of CVE-2026-88772 exploitation occurred Sept. 3, Mandiant researchers told CyberScoop Tuesday.
The besieged security vendor and researchers didn’t confirm the attacks until late last week. By then, Mandiant says, organizations in North America and Europe spanning the government, financial services, education, telecom, legal and professional services sectors were already likely compromised.
“We are aware of dozens of impacted organizations,” Charles Carmakal, chief technology officer at Mandiant Consulting, wrote in a LinkedIn post. He attributed the attacks to “advanced and suspected state-sponsored threat actors.”
The three-week gap — at minimum — between initial exploitation and confirmed in-the-wild attacks gave attackers a significant advantage.
Mandiant warned that the gap could be even wider. “We are still responding to active intrusions, and new evidence may change our understanding of the campaign timeline,” researchers who published a threat intelligence report on the attacks Tuesday told CyberScoop in an email.
The incident response firm’s analysis on the latest zero-day attack spree targeting Citrix customers underscores the multi-layered mess network defenders have been responding to since Saturday.
The zero-day exploits in Mandiant’s report only cover half of the problem. Attackers have also exploited a second Citrix NetScaler zero-day — CVE-2026-88771 — since at least Sept. 24, according to GreyNoise, but researchers said that campaign likely started earlier as well.
It’s unclear to what extent the pair of zero-days are linked. But, nearly two days after the first unconfirmed rumors of the attacks surfaced, Citrix disclosed both of the actively exploited defects in a security advisory Sunday, releasing patches for them and six additional vulnerabilities.
Mandiant researchers uncovered multiple novel tools and tactics attackers used to exploit CVE-2026-88772, gain privileged access to compromised environments, hop around the network and steal sensitive data. A threat actor in one observed intrusion routed traffic through novel tunneler malware to “manually conduct internal reconnaissance and credential theft,” researchers wrote.
Researchers at watchTowr also published technical analysis of CVE-2026-88782 Tuesday.
The attacks from multiple fronts, involving two zero-days, reflect an alarming and sustained pattern of malicious activity targeting so-called edge devices, such as virtual private network gateways and firewalls.
Vulnerabilities in these devices accounted for 48% of the enterprise-related zero-days last year, according to Google Threat Intelligence Group.
“Our previous research corroborates that both cyber espionage and financially motivated threat actors prioritize exploiting vulnerabilities in edge devices and security appliances,” Mandiant researchers wrote in response to questions on their report.
“Because most edge devices do not support endpoint detection and response (EDR) monitoring, targeting them, particularly through exploiting zero-day vulnerabilities, provides threat actors with an infection vector that is difficult to detect and prevent, and the opportunity to scale a campaign as long as the exploit remains undiscovered,” the researchers added.
Carmakal, in his LinkedIn post, warned that Mandiant expects “broad and opportunistic exploitation” of both of the Citrix NetScaler zero-days by a variety of threat actors in the near term.
Latest Podcasts
Government
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
As AI world debates security, NVIDIA releases open source tools for agents
ShinyHunters trades financial extortion for a reckless war of ego with the FBI
Supreme Court permits states to use SAVE database for citizenship checks
Technology
Threats
Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
Ryuk ransomware operator sentenced to 2 years in prison