Citrix Zero-Day Attacks Hit Governments, Banks and Law Firms: Patch Isn't Enough
Citrix has disclosed eight vulnerabilities affecting its NetScaler ADC and NetScaler Gateway appliances, including two critical flaws, CVE-2026-88771 and CVE-2026-88772, that were actively exploited before they were publicly revealed. Security researchers say attackers used custom malware to break into government agencies, banks, education providers and legal and professional services firms across North America and Europe, with exploitation dating back to at least early September.
Security experts have criticised Citrix for taking too long to disclose the flaws, noting that the vulnerabilities were only discovered during forensic investigations of organisations that had already been compromised. This means both the attacks and Citrix's own awareness of them predated the public advisory.
Mandiant's Charles Carmakal has warned that NetScaler customers should check their systems for signs of compromise, such as web shells or other malicious files, before applying patches. Simply patching the vulnerability may not remove an attacker who has already established a foothold in the network.