Advertisement

Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected

Mandiant researchers said dozens of organizations have been impacted by attacks attributed to advanced and suspected state-sponsored threat groups. They expect more attacks to come.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
Hackers stealing data concept.
Hackers stealing data concept. (Getty Images)

Attackers remained undetected for more than three weeks as they exploited a critical zero-day vulnerability affecting Citrix NetScaler appliances en masse. 

The earliest known instance of CVE-2026-88772 exploitation occurred Sept. 3, Mandiant researchers told CyberScoop Tuesday. 

The besieged security vendor and researchers didn’t confirm the attacks until late last week. By then, Mandiant says, organizations in North America and Europe spanning the government, financial services, education, telecom, legal and professional services sectors were already likely compromised.

“We are aware of dozens of impacted organizations,” Charles Carmakal, chief technology officer at Mandiant Consulting, wrote in a LinkedIn post. He attributed the attacks to “advanced and suspected state-sponsored threat actors.”

Advertisement

The three-week gap — at minimum — between initial exploitation and confirmed in-the-wild attacks gave attackers a significant advantage. 

Mandiant warned that the gap could be even wider. “We are still responding to active intrusions, and new evidence may change our understanding of the campaign timeline,” researchers who published a threat intelligence report on the attacks Tuesday told CyberScoop in an email. 

The incident response firm’s analysis on the latest zero-day attack spree targeting Citrix customers underscores the multi-layered mess network defenders have been responding to since Saturday.

The zero-day exploits in Mandiant’s report only cover half of the problem. Attackers have also exploited a second Citrix NetScaler zero-day — CVE-2026-88771 — since at least Sept. 24, according to GreyNoise, but researchers said that campaign likely started earlier as well.

It’s unclear to what extent the pair of zero-days are linked. But, nearly two days after the first unconfirmed rumors of the attacks surfaced, Citrix disclosed both of the actively exploited defects in a security advisory Sunday, releasing patches for them and six additional vulnerabilities.

Advertisement

Mandiant researchers uncovered multiple novel tools and tactics attackers used to exploit CVE-2026-88772, gain privileged access to compromised environments, hop around the network and steal sensitive data. A threat actor in one observed intrusion routed traffic through novel tunneler malware to “manually conduct internal reconnaissance and credential theft,” researchers wrote. 

Researchers at watchTowr also published technical analysis of CVE-2026-88782 Tuesday.

The attacks from multiple fronts, involving two zero-days, reflect an alarming and sustained pattern of malicious activity targeting so-called edge devices, such as virtual private network gateways and firewalls. 

Vulnerabilities in these devices accounted for 48% of the enterprise-related zero-days last year, according to Google Threat Intelligence Group.

“Our previous research corroborates that both cyber espionage and financially motivated threat actors prioritize exploiting vulnerabilities in edge devices and security appliances,” Mandiant researchers wrote in response to questions on their report. 

Advertisement

“Because most edge devices do not support endpoint detection and response (EDR) monitoring, targeting them, particularly through exploiting zero-day vulnerabilities, provides threat actors with an infection vector that is difficult to detect and prevent, and the opportunity to scale a campaign as long as the exploit remains undiscovered,” the researchers added. 

Carmakal, in his LinkedIn post, warned that Mandiant expects “broad and opportunistic exploitation” of both of the Citrix NetScaler zero-days by a variety of threat actors in the near term.

Latest Podcasts