Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Attackers remained undetected for more than three weeks as they exploited a critical zero-day vulnerability affecting Citrix NetScaler appliances en masse.
The earliest known instance of CVE-2026-88772 exploitation occurred Sept. 3, Mandiant researchers told CyberScoop Tuesday.
The besieged security vendor and researchers didn’t confirm the attacks until late last week. By then, Mandiant says, organizations in North America and Europe spanning the government, financial services, education, telecom, legal and professional services sectors were already likely compromised.
“We are aware of dozens of impacted organizations,” Charles Carmakal, chief technology officer at Mandiant Consulting, wrote in a LinkedIn post. He attributed the attacks to “advanced and suspected state-sponsored threat actors.”
The three-week gap — at minimum — between initial exploitation and confirmed in-the-wild attacks gave attackers a significant advantage…