Suspected State Hackers Exploited Citrix NetScaler for Weeks. 50,000 Devices May Still Be Exposed.
Suspected state hackers exploited two Citrix NetScaler zero-days; about 50,000 devices may remain exposed.
Two unauthenticated remote-code-execution flaws in Citrix NetScaler ADC and NetScaler Gateway, CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5, were exploited as zero-days against organizations worldwide before patches existed. Suspected state-backed hackers used them for weeks, and both are in CISA's Known Exploited Vulnerabilities catalog. Federal civilian agencies faced a remediation and forensic-triage deadline of September 30, 2026. Fixed versions are 14.1-73.37 and 13.1-64.23, with FIPS/NDcPP build 13.1-37.279; reporting says about 50,000 devices may still be exposed, and patching alone does not show prior compromise.
- CVE-2026-88771 and CVE-2026-88772 are unauthenticated NetScaler RCE flaws, CVSS 9.5.
- Both were exploited as zero-days and are listed in CISA KEV.
- About 50,000 devices may still be exposed.
- Federal agencies had to patch and triage by September 30, 2026.
- Fixed builds include 14.1-73.37 and 13.1-64.23.
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article96 words · extracted from databreaches.net · click to collapse
Datawater reports:
Two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, were used against organizations worldwide before a patch existed. CISA’s deadline is today. Patching alone will not tell you whether you were already breached.
Threat level: Critical
What: Two unauthenticated remote-code-execution flaws in Citrix NetScaler ADC and NetScaler Gateway, both CVSS 9.5.
Status: Exploited as zero-days. Listed in CISA’s Known Exploited Vulnerabilities catalog.
Deadline: Federal civilian agencies must remediate and perform forensic triage by today, September 30, 2026.
Fix: Upgrade to 14.1-73.37 or 13.1-64.23 (FIPS/NDcPP: 13.1-37.279). Then hunt for compromise.
Read the full report on Datawater.
Text extracted automatically; images, tables and formatting may be missing. Original: https://databreaches.net/2026/10/01/suspected-state-hackers-exploited-citrix-netscaler-for-weeks-50000-devices-may-still-be-exposed/