Security News

Citrix NetScaler Zero-Day Attacks Went Undetected for Weeks, Dozens of Organisations Hit

CyberScoop · 30 Sept 2026
Key Takeaway Australian businesses using Citrix NetScaler appliances should apply the latest security patches immediately and review network logs for signs of compromise dating back to early September.

Security researchers at Mandiant have confirmed that a critical vulnerability affecting Citrix NetScaler appliances, tracked as CVE-2026-88772, was being actively exploited as early as September 3, but was not publicly confirmed until late last week. By the time the exploitation was verified, dozens of organisations across North America and Europe, spanning government, financial services, education, telecom, and legal sectors, were likely already compromised. Mandiant has attributed the attacks to advanced and suspected state-sponsored threat actors and says it is still responding to active intrusions.

Adding to the complexity, a second Citrix NetScaler zero-day, CVE-2026-88771, has reportedly been exploited since at least September 24, according to research from GreyNoise, with some evidence suggesting the campaign may have started even earlier. It remains unclear whether the two vulnerabilities are connected as part of the same campaign. Citrix confirmed both actively exploited flaws in a security advisory, releasing patches for these along with six additional vulnerabilities.

The weeks-long gap between initial exploitation and public disclosure gave attackers a significant head start, allowing them to establish footholds inside victim networks before defenders were even aware of the threat. This incident highlights how quickly attackers can move against widely used enterprise infrastructure once a flaw is discovered, often well before vendors or researchers catch on.

Summarised by CISO AI from CyberScoop. We link back to every original so you can read it yourself.