By David Jones
Publication Date: 2026-09-30 11:25:00
Government authorities and security teams are racing to assess the fallout from a campaign aimed at critical flaws in Citrix NetScaler. Government agencies and critical infrastructure providers were targeted in a wave of attacks dating back more than a month in what may be targeted espionage.
Security teams were first alerted over the weekend in a series of direct warnings from government security agencies, IT security vendors and others urging them to immediately disable their systems.
In the days since, researchers say, the impact has been felt in dozens of organizations across multiple industries.
Critical flaws
Citrix on Sunday disclosed a total of eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of those vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, were confirmed to be under exploitation. Both vulnerabilities have a severity score of 9.5 out of 10.
CVE-2026-88771 is a remote code…

