By Eduard Kovacs
Publication Date: 2026-09-30 12:48:00
Google’s Mandiant and Threat Intelligence Group (GTIG) have published details on attacks exploiting the NetScaler zero-days that Citrix patched over the weekend.
The vulnerabilities are tracked as CVE-2026-88771 and CVE-2026-88772, and they affect NetScaler ADC and NetScaler Gateway instances. Attackers can exploit these critical flaws for unauthenticated remote code execution.
Before Citrix released patches, government cybersecurity agencies and security firms took the rare step of urging administrators to disconnect affected NetScaler appliances from the internet immediately while zero-day exploitation investigations were ongoing.
Mandiant and GTIG, whose report focuses on the exploitation of CVE-2026-88772, spotted attacks in late September. However, their investigation found that the zero-day campaign has been “ongoing since at least early September.”
The attacks likely impacted organizations in North America and Europe. These organizations are in the…



