Published Wednesday, September 30, 2026 at 11:44 AM PT

<strong>BREAKING: State-Sponsored Actors Exploit Citrix NetScaler RCE Zero-Days; Mass Exploitation Underway Since Early September</strong>

BLUF: Suspected state-sponsored threat actors are exploiting two critical remote code execution zero-days in Citrix NetScaler ADC and Gateway (CVE-2026-88771, CVE-2026-88772). Active exploitation began in early September 2026 and has escalated from targeted intrusions to mass attacks affecting organizations globally. Organizations running vulnerable NetScaler instances must patch immediately.

DETAILS:

  • Two critical RCE zero-days: CVE-2026-88771 and CVE-2026-88772 affect Citrix NetScaler ADC and Gateway. Both have been actively exploited in the wild. Patches have been released by Citrix; specific patch versions and affected product versions are not detailed in available advisories.

  • Timeline and scope: Initial targeted intrusions leveraging CVE-2026-88772 began in early September 2026. Exploitation has since escalated into widespread mass attacks affecting organizations globally, according to Mandiant analysis and multiple security vendors.

  • Threat actor profile: Mandiant assesses the initial intrusions as “advanced and suspected state-sponsored.” Attribution is incomplete; nation-state identity remains unconfirmed. Exploitation pattern suggests capability maturation and operational shift from precise targeting to volume attacks.

  • Active exploitation confirmed: Unit 42 (Palo Alto), SOC Prime, CSO Online, SecurityWeek, and The Hacker News independently confirm active exploitation in the wild. No embargo period remains; patching is urgent rather than preventive.

IMPACT:

  • Primary targets: Internet-facing NetScaler deployments used for application delivery, VPN gateway access, and load balancing. Organizations in critical infrastructure, finance, government, and enterprise are likely prioritized.
  • Attack surface: Any organization exposing NetScaler ADC or Gateway to the internet without patches is exploitable.
  • Scope uncertainty: Confirmed global exploitation; exact count of compromised systems not disclosed. Mass attack phase suggests hundreds to potentially thousands of vulnerable instances remain unpatched.

RECOMMENDED ACTIONS:

  1. Immediate (24–48 hours): Audit all Citrix NetScaler ADC and Gateway instances in your environment. Identify public-facing or VPN-facing deployments.
  2. Deploy patches: Apply Citrix-provided patches to all vulnerable NetScaler instances. Test in staging first if production outage risk is severe, but prioritize speed.
  3. Threat hunting: If NetScaler instances were exposed during early September–now, assume possible compromise. Review access logs, query DNS for lateral movement, inspect running processes for backdoors.
  4. Compensating controls (if patching is delayed): Restrict NetScaler administrative interfaces to trusted IP ranges. Enable detailed logging of ADC/Gateway access and module loads.

SOURCES:

  • Mandiant (cha quote — advisory in progress)
  • Unit 42 Palo Alto Networks
  • SOC Prime
  • CSO Online / Citrix advisory
  • SecurityWeek
  • The Hacker News
  • news4hackers

Recent high-severity events at publish time:

Recent high-severity events