Exploitation activity linked to zero-day vulnerabilities in Citrix NetScaler were initially detected on Thursday, days before public disclosure, according to a report Monday from GreyNoise.
A malicious cyber actor tried to exploit a zero-day flaw against Citrix NetScaler on Thursday, according to GreyNoise researchers. At the time, there were no detections available that were specific to this CVE, but researchers labeled the activity malicious.
Two days later, Citrix NetScaler customers began receiving warnings to disconnect their servers due to suspected exploitation activity. By Sunday, Citrix released an official security bulletin warning of multiple vulnerabilities in NetScaler ADC and NetScaler Gateway.
The exploitation activity involved a remote code execution (RCE) vulnerability, tracked as CVE-2026-88771 and a memory overflow vulnerability, tracked as CVE-2026-88772.
Citrix urged customers to immediately patch their systems, warning that successful exploitation could result in RCE, denial of service, HTTP request smuggling and other consequences.
“We always advise customers to promptly adopt the latest version of our software, and we are underscoring that guidance here to ensure our customers immediately benefit from the updates in this latest release,” a Citrix spokesperson told Cybersecurity Dive.
The Cybersecurity and Infrastructure Security Agency issued its own advisory on the threat activity and added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog on Sunday.
Widespread impacts
Researchers at Shadowserver Foundation on Monday said they were aware of successful exploitation attempts and more than 20,000 instances were visible and potentially vulnerable. Researchers at GreyNoise and Mandiant identified specific post-exploitation activity in recent days.
“The threat actor deployed web shells on compromised NetScaler systems and moved laterally to internal networks on some of the targeted organizations,” Charles Carmakal, CTO and board advisor at Mandiant Consulting, the incident response arm of Google Threat Intelligence Group, said in a LinkedIn post on Monday.
Carmakal warned that customers should check to determine whether they have been compromised before upgrading to the new patched version. Patching without taking the other steps might not resolve the infection.
He noted that Citrix released a scanner to check for indicators of compromise and a file integrity monitor to determine if NetScaler has been compromised.