By Zeljka Zorz
Publication Date: 2026-09-29 14:59:00
The hacking of internet-exposed, vulnerable Citrix NetScaler ADC and Gateway deployments has escalated.
What started as stealthy targeting via zero-day exploits has now become widespread “spray and pray” exploitation, fueled by the publication of a root-cause analysis and a proof-of-concept exploit for CVE-2026-88771, which is remotely exploitable on unpatched devices with the default configuration.
From rumor to confirmed zero-day
Rumors about a NetScaler zero-day being exploited in the wild started late last week, and were confirmed when Citrix published a security advisory after the release of patches for eight critical and high-risk vulnerabilities.
Among those are CVE-2026-88771 and CVE-2026-88772, both both exploited as zero-days.
Citrix also provided a detection script customers could use to check for evidence of compromise, but acknowledged it “might fail to identify actual compromises” since attackers often change tactics, techniques, and procedures…


