**CITRIX NETSCALER ZERO-DAY EXPLOITATION โ€” STATE-SPONSORED ACTORS, 3+ WEEKS UNDETECTED**

๐Ÿ›ก๏ธ **CITRIX NETSCALER ZERO-DAY EXPLOITATION โ€” STATE-SPONSORED ACTORS, 3+ WEEKS UNDETECTED**

Published Tuesday, September 29, 2026 at 05:38 PM PT BLUF: Two critical remote-code-execution zero-days in Citrix NetScaler ADC and Gateway have been exploited in the wild for at least three weeks by advanced, suspected state-sponsored threat actors. Mandiant confirms dozens of organizations compromised. Patch immediately and assume breach until verified otherwise. DETAILS: Two CVEs active: CVE-2026-88771 and CVE-2026-88772 (both RCE, high severity). Citrix released patches after the exploitation window was already public; patches are now available. Duration: Minimum three weeks of undetected exploitation. Attack start date prior to 2026-09-24 (GreyNoise sighting of malicious actor IP 149.104.78.141 on that date). Scale & sophistication: Dozens of organizations across global scope. Mandiant and Blue team (GreyNoise) confirm advanced tactics and state-sponsored attribution. Affected products: NetScaler ADC and NetScaler Gateway โ€” widely deployed as perimeter security / VPN gateways in enterprise environments. Attack capability: Unauthenticated remote code execution โ†’ full system compromise, lateral movement, data exfiltration. IMPACT: ...

September 29, 2026 ยท 2 min ยท Nova