Citrix NetScaler zero-days exploited in weeks-long campaign against government and finance

Medium · SecurityWeek ·

Exploited

Key points

  • Two Citrix NetScaler flaws are under active zero-day exploitation.
  • Targets include public-sector and financial-sector organizations.
  • The campaign has lasted several weeks and is tracked by multiple security vendors.
  • The attackers remain unidentified, and exploitation has been confirmed.

Security personnel have verified that unknown threat actors are currently leveraging two vulnerabilities in Citrix NetScaler, designated CVE-2026-88771 and CVE-2026-88772. This operation is being classified as zero-day exploitation, and the compromises appear directed at selected targets rather than widespread scanning.

Public-sector agencies and financial institutions are among the affected targets. Because NetScaler appliances often sit at the edge of enterprise networks and broker access to internal applications, a successful compromise can give attackers a valuable foothold. That makes the campaign especially concerning for organizations that rely on the product for remote access or application delivery.

The campaign has persisted for several weeks and has drawn attention from more than one security vendor. Although the attackers remain unknown, confirmed exploitation and the targeted nature of the attacks suggest a deliberate effort. The two CVEs are the common thread across observed incidents.

At this stage, defenders should assume that unpatched or exposed NetScaler systems may be at risk. Organizations in government and finance should prioritize visibility into appliance logs, authentication events, and configuration changes. They should also watch for vendor advisories, updated indicators, and any signs of lateral movement from NetScaler infrastructure into protected environments.

Key unknowns include the full victim list, the attackers' identity, and whether additional flaws are involved. Until more is known, treating NetScaler as a high-value target and reducing its exposure are prudent steps. Incident response plans should be ready if suspicious activity is confirmed.

What to do now

  1. Inventory every Citrix NetScaler instance and identify versions affected by CVE-2026-88771 and CVE-2026-88772.
  2. Apply Citrix mitigations or updates as soon as vendor guidance is available; if no fix exists, restrict exposure immediately.
  3. Limit management interfaces and remote access to trusted networks, and enforce multi-factor authentication where possible.
  4. Review NetScaler logs for unusual authentication, configuration changes, or outbound connections tied to the appliance.
  5. Hunt for indicators published by the security vendors tracking the weeks-long campaign.
  6. Segment NetScaler appliances from critical government and finance systems to reduce lateral movement risk.
  7. Escalate confirmed compromise to incident response and preserve forensic evidence.

CVE references

  • CVE-2026-88771
  • CVE-2026-88772

Original source

SecurityWeek

Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news