Suspected State Hackers Exploited Citrix NetScaler for Weeks; 50,000 Devices May Still Be Exposed
Executive Summary
Datawater reports that two unauthenticated remote‑code‑execution zero‑day vulnerabilities in Citrix NetScaler ADC and Gateway (CVE‑2026‑88771 and CVE‑2026‑88772) were actively exploited worldwide for weeks before a patch was available. The attacks, attributed to suspected state actors, could have compromised up to 50,000 devices. CISA has set a patch deadline for today, but remediation alone does not confirm whether an organization was breached. The flaws carry a CVSS score of 9.5 and are classified as critical.
Intelligence Metadata - Source Publisher: DataBreaches.net - Published Date: 2026-10-01T11:55:42+00:00 - Category: vulnerabilities
Original Description: Datawater reports: Two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, were used against organizations worldwide before a patch existed. CISA’s deadline is today. Patching alone will not tell you whether you were already breached. Threat level: Critical What: Two unauthenticated remote-code-execution flaws in Citrix NetScaler ADC and NetScaler Gateway, both CVSS 9.5. Status: Exploited as zero-days.... Source
"Every person, all the events of your life are there because you have drawn them there. What you choose to do with them is up to you."
— Richard Bach