Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772) – Help Net Security

Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772) – Help Net Security

By Zeljka Zorz
Publication Date: 2026-09-30 12:33:00

“Advanced and suspected state-sponsored threat actors” are likely to be behind the initial targeted intrusions that leveraged CVE-2026-88772, one of the two recently disclosed NetScaler vulnerabilities that have been exploited as zero-days, says Mandiant CTO Charles Carmakal.

Mandiant and Google Threat Intelligence Group (GTIG) know of dozens of impacted organizations across North America and Europe, he added, “including in the government, financial services, education, telecommunications, and legal and professional services sectors.”

Two NetScaler zero-days exploited

On September 27, 2026, a few days after organizations around the world began getting notified of active attacks involving a possible zero-day vulnerability in Citrix NetScaler ADCs and Gateways, Citrix confirmed that two flaws had been exploited: CVE-2026-88771 and CVE-2026-88772.

Both allow remote attackers to achieve remote code execution on vulnerable appliances. While the former works on all…