Government, finance organizations targeted in NetScaler zero-day attacks
Summary
Government and financial organizations have been targeted in a series of weeks-long cyber attacks exploiting vulnerabilities in Citrix NetScaler appliances. Reports from Mandiant and Google Threat Intelligence reveal that these attacks have impacted various sectors, including government, finance, education, technology, and legal, across North America and Europe. The campaign specifically involved two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, which allowed unauthorized remote code execution. In response, Citrix has issued security updates, while CISA has instructed U.S. federal agencies to secure or disconnect affected systems to mitigate further risks.
Analysis
Response: Citrix released security updates after confirming exploitation, while CISA directed U.S. federal agencies to secure affected systems or disconnect vulnerable appliances. Attack_scope: Mandiant and Google Threat Intelligence reported active exploitation of Citrix NetScaler appliances affecting organizations in government, financial services, education, technology, and legal sectors across North America and Europe. Vulnerabilities: The campaign involved two actively exploited NetScaler flaws, CVE-2026-88771 and CVE-2026-88772, including an unauthenticated remote-code-execution vulnerability.
Categories
politicstech
Related sources
- https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances
- https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867
- https://cyberscoop.com/citrix-netscaler-zero-day-attacks-three-weeks-undetected/
- https://aviatrix.ai/threat-research-center/citrix-netscaler-cve-2026-88772-zero-day-web-shells/
- https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/
- https://aviatrix.ai/threat-research-center/citrix-netscaler-zero-day-cve-2026-88771-88772-rce-exploitation/
- https://thehackernews.com/search/label/Vulnerability
- https://labs.cloudsecurityalliance.org/research/csa-research-note-citrix-netscaler-zero-day-kev-20260928-csa/
- https://sqmagazine.co.uk/citrix-netscaler-zero-days-exploited/
- https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/
- https://www.bleepingcomputer.com/tag/netscaler/
- https://aviatrix.ai/threat-research-center/citrix-netscaler-unpatched-rce-zero-days-2026/
- https://www.itnews.com.au/news/citrix-confirms-exploitation-of-netscaler-zero-day-bugs-629232
- https://securityaffairs.com/199873/security/citrix-confirmed-two-new-netscaler-flaws-exploited-as-zero-day.html
- https://www.bankinfosecurity.com/hackers-hit-netscaler-zero-days-before-citrix-patched-a-32959