Attackers exploited a critical zero-day vulnerability in Citrix NetScaler appliances for at least three weeks before its public disclosure and the release of patches, according to security researchers. The vulnerability, identified as CVE-2026-88772, was first exploited on September 3, with widespread attacks affecting dozens of organizations across North America and Europe. These organizations span various sectors, including government, financial services, education, telecommunications, legal, and professional services.
Mandiant researchers, who have been responding to active intrusions, attributed the attacks to advanced and suspected state-sponsored threat actors. The significant time gap between initial exploitation and confirmed in-the-wild attacks provided attackers with a considerable advantage, allowing them to compromise numerous systems undetected. Researchers cautioned that the actual timeline of exploitation could be even wider as new evidence emerges.
In addition to CVE-2026-88772, a second Citrix NetScaler zero-day, CVE-2026-88771, has also been actively exploited since at least September 24, though researchers suspect its exploitation may have begun earlier. The extent to which these two zero-days are linked remains unclear. Citrix officially disclosed both actively exploited vulnerabilities in a security advisory on Sunday, releasing patches for them along with six other vulnerabilities.
Mandiant’s analysis revealed that attackers utilized novel tools and tactics to exploit CVE-2026-88772. These methods allowed them to gain privileged access within compromised environments, move laterally across networks, and exfiltrate sensitive data. In one observed intrusion, a threat actor routed traffic through new tunneler malware to conduct manual internal reconnaissance and credential theft. WatchTowr researchers also published technical analysis of CVE-2026-88782, another vulnerability related to these attacks.
The ongoing attacks, involving multiple zero-days, highlight a concerning trend of malicious activity targeting edge devices such as virtual private network gateways and firewalls. Last year, vulnerabilities in these types of devices accounted for 48% of enterprise-related zero-day exploits, according to Google Threat Intelligence Group. Both cyber espionage and financially motivated threat actors prioritize exploiting vulnerabilities in edge devices and security appliances.
The difficulty in detecting and preventing attacks on edge devices stems from their typical lack of support for endpoint detection and response (EDR) monitoring. This makes them an attractive infection vector for threat actors, providing an opportunity to scale campaigns as long as the exploits remain undiscovered. Mandiant anticipates broad and opportunistic exploitation of both Citrix NetScaler zero-days by a diverse range of threat actors in the near future.






