Citrix NetScaler zero-day exploited three weeks before disclosure
Mandiant traced the earliest CVE-2026-88772 exploitation to September 3, meaning defenders lost at least 21 days before Citrix confirmed the attacks.
TL;DR
Mandiant says attackers exploited CVE-2026-88772 (one of two actively targeted Citrix NetScaler zero-days) as early as September 3, more than three weeks before Citrix disclosed the vulnerability Sunday. Organizations in government, financial services, education, telecom, legal, and professional services in North America and Europe were affected. Attackers used novel tunneler malware in at least one intrusion to conduct internal reconnaissance and steal credentials. CISA added both exploited CVEs to its Known Exploited Vulnerabilities catalog and urged organizations to check for signs of compromise before patching.
The disclosure timeline on the latest Citrix NetScaler zero-days keeps getting worse. Mandiant told CyberScoop on Tuesday that exploitation of CVE-2026-88772 began at least September 3, a full 25 days before Citrix published its security advisory on Sunday confirming active attacks. The incident response firm said it is tracking "dozens of impacted organizations" across government, financial services, education, telecom, legal, and professional services in North America and Europe, attributing the campaign to advanced, suspected state-sponsored actors.
The delay compounds an already damaging communication gap. Rumors of active exploitation circulated Friday and Saturday through CERTs, advisory firms, and security professionals. Citrix remained publicly silent until Sunday, when it disclosed CVE-2026-88771 and CVE-2026-88772 alongside six additional vulnerabilities. Both zero-days carry CVSS scores of 9.5 and enable remote code execution. CISA added them to its Known Exploited Vulnerabilities catalog and issued an alert emphasizing that organizations should check for indicators of compromise before applying updates, since patching can destroy forensic evidence.
Mandiant's report details how attackers leveraged CVE-2026-88772 to gain privileged access, then deployed novel tunneler malware to move laterally and steal credentials. Researchers warned the three-week window may understate the true exposure, "new evidence may change our understanding of the campaign timeline," they told CyberScoop. The firm expects broad, opportunistic exploitation of both zero-days to accelerate.
The pattern is familiar in outcome if not in specifics. Vulnerabilities in edge devices like VPN gateways accounted for 48% of enterprise-targeted zero-days last year, per Google Threat Intelligence Group. Because most edge devices don't support endpoint detection and response, attackers who find a zero-day can operate at scale until someone notices. This time, that took the better part of a month.
Published ·Deep Fathom