By Divya
Publication Date: 2026-09-30 09:47:00
Threat actors are actively exploiting a critical zero-day vulnerability in Citrix NetScaler, identified as CVE-2026-88772, to gain unauthenticated root-level access to vulnerable Application Delivery Controller (ADC) and Gateway appliances.
After the initial compromise, they deploy custom PHP web shells and tools to tunnel within the internal network. Mandiant Consulting and the Google Threat Intelligence Group (GTIG) reported that this campaign has been active since at least early September and has impacted organizations in North America and Europe.
This vulnerability affects NetScaler ADC and NetScaler Gateway deployments that have Datagram Transport Layer Security (DTLS) enabled, which is the default setting on VPN virtual servers.
Citrix assigned a CVSS v4 score of 9.5 to this bug and confirmed that it has been exploited in attacks against systems that have not applied mitigations.
Citrix NetScaler Zero-Day
CVE-2026-88772 is a memory overflow issue in the…


