Citrix NetScaler Zero-Days Exploited in Global Campaign, NCSC-NL Warns
High · Help Net Security ·
Exploited
Verification: The article is future-dated relative to the current date and relies on rumors and unverified supplier warnings, so the claimed security event cannot be confirmed as real.
Key points
- Attackers used two zero-days in Citrix NetScaler ADC and Gateway, tracked as CVE-2026-88771 and CVE-2026-88772.
- The campaign has run for weeks, targeting organizations globally and involving eight vulnerabilities total.
- NCSC-NL issued warnings, and Kevin Beaumont plus European government sources corroborated the activity.
- Patches are available, but web shells and device compromise require immediate incident response.
On Friday, 2026-09-28, details emerged about a sustained attack against Citrix NetScaler ADC and NetScaler Gateway. According to NCSC-NL, European government sources, and researcher Kevin Beaumont, threat actors leveraged two zero-day flaws—CVE-2026-88771 and CVE-2026-88772—to run code remotely and take over devices. The operation is worldwide and has persisted for several weeks, with eight vulnerabilities tied to the broader campaign.
Organizations with exposed NetScaler appliances are in the crosshairs, particularly government agencies and critical service providers. IT suppliers have also been drawn into the response. Warnings were issued by NCSC-NL, while rumors about the intrusions surfaced before official confirmation. Beaumont's public analysis helped connect the dots for defenders.
The impact goes beyond a simple breach. Attackers planted web shells, granting persistent access that can survive patching. A compromised device may serve as a beachhead for lateral movement, data theft, or further malware deployment. Because the campaign has run for weeks, some victims may already be deeply penetrated without knowing it.
Citrix has released patches for the vulnerabilities, but exploitation occurred before fixes were available. The total of eight flaws suggests a coordinated scanning and exploitation effort rather than an isolated incident. Global reach means no region or sector should assume it is safe.
Defenders should watch for additional CVEs, updated advisories, and signs of web shell activity. The situation remains fluid; the number of affected organizations could grow. Immediate triage and forensic review are essential, even on patched systems.
What to do now
- Immediately inventory all NetScaler ADC and Gateway appliances, and identify which versions are affected by CVE-2026-88771 and CVE-2026-88772.
- Apply Citrix's latest patches without delay; if patching is not possible, isolate or take affected systems offline until remediation is complete.
- Hunt for web shells and other persistence mechanisms on NetScaler devices and connected systems, reviewing logs for unusual commands or file writes.
- Reset credentials and rotate secrets for any accounts that could have been exposed through compromised devices.
- Enable enhanced logging and monitoring for NetScaler, and review historical logs for signs of exploitation dating back several weeks.
- Consult NCSC-NL and vendor advisories for indicators of compromise, and share findings with sector peers and government contacts.
- If compromise is confirmed, engage incident response and consider a full rebuild of affected appliances rather than relying on cleanup alone.
CVE references
- CVE-2026-88771
- CVE-2026-88772
Original source
Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.