Published Wednesday, September 30, 2026 at 11:44 AM PT

BLUF: Suspected state-sponsored threat actors are exploiting two critical remote code execution zero-days in Citrix NetScaler ADC and Gateway (CVE-2026-88771, CVE-2026-88772). Active exploitation began in early September 2026 and has escalated from targeted intrusions to mass attacks affecting organizations globally. Organizations running vulnerable NetScaler instances must patch immediately.
DETAILS:
Two critical RCE zero-days: CVE-2026-88771 and CVE-2026-88772 affect Citrix NetScaler ADC and Gateway. Both have been actively exploited in the wild. Patches have been released by Citrix; specific patch versions and affected product versions are not detailed in available advisories.
Timeline and scope: Initial targeted intrusions leveraging CVE-2026-88772 began in early September 2026. Exploitation has since escalated into widespread mass attacks affecting organizations globally, according to Mandiant analysis and multiple security vendors.
Threat actor profile: Mandiant assesses the initial intrusions as “advanced and suspected state-sponsored.” Attribution is incomplete; nation-state identity remains unconfirmed. Exploitation pattern suggests capability maturation and operational shift from precise targeting to volume attacks.
Active exploitation confirmed: Unit 42 (Palo Alto), SOC Prime, CSO Online, SecurityWeek, and The Hacker News independently confirm active exploitation in the wild. No embargo period remains; patching is urgent rather than preventive.
IMPACT:
- Primary targets: Internet-facing NetScaler deployments used for application delivery, VPN gateway access, and load balancing. Organizations in critical infrastructure, finance, government, and enterprise are likely prioritized.
- Attack surface: Any organization exposing NetScaler ADC or Gateway to the internet without patches is exploitable.
- Scope uncertainty: Confirmed global exploitation; exact count of compromised systems not disclosed. Mass attack phase suggests hundreds to potentially thousands of vulnerable instances remain unpatched.
RECOMMENDED ACTIONS:
- Immediate (24–48 hours): Audit all Citrix NetScaler ADC and Gateway instances in your environment. Identify public-facing or VPN-facing deployments.
- Deploy patches: Apply Citrix-provided patches to all vulnerable NetScaler instances. Test in staging first if production outage risk is severe, but prioritize speed.
- Threat hunting: If NetScaler instances were exposed during early September–now, assume possible compromise. Review access logs, query DNS for lateral movement, inspect running processes for backdoors.
- Compensating controls (if patching is delayed): Restrict NetScaler administrative interfaces to trusted IP ranges. Enable detailed logging of ADC/Gateway access and module loads.
SOURCES:
- Mandiant (cha quote — advisory in progress)
- Unit 42 Palo Alto Networks
- SOC Prime
- CSO Online / Citrix advisory
- SecurityWeek
- The Hacker News
- news4hackers
Recent high-severity events at publish time:

