Citrix NetScaler exploitation began days before public notification

Citrix NetScaler exploitation began days before public notification

By David Jones
Publication Date: 2026-09-29 11:06:00

Exploitation activity linked to zero-day vulnerabilities in Citrix NetScaler were initially detected on Thursday, days before public disclosure, according to a report Monday from GreyNoise. 

A malicious cyber actor tried to exploit a zero-day flaw against Citrix NetScaler on Thursday, according to GreyNoise researchers. At the time, there were no detections available that were specific to this CVE, but researchers labeled the activity malicious. 

Two days later, Citrix NetScaler customers began receiving warnings to disconnect their servers due to suspected exploitation activity. By Sunday, Citrix released an official security bulletin warning of multiple vulnerabilities in NetScaler ADC and NetScaler Gateway. 

The exploitation activity involved a remote code execution (RCE) vulnerability, tracked as CVE-2026-88771 and a memory overflow vulnerability, tracked as CVE-2026-88772. 

Citrix urged customers to immediately patch…