Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-30 · updated: 2026-09-30 · tags: [incident, global] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: true

The Citrix NetScaler zero-days moved from an emergency patching story to a documented intrusion campaign, as Mandiant and watchTowr published forensic detail on attackers exploiting CVE-2026-88772 to deploy custom web shells and tunnelling malware, gain root, steal credentials and spread into internal networks. Mandiant says the attacks began in at least early September and are believed to have affected organisations in North America and Europe across the government, financial services, education, legal and professional services sectors. GreyNoise observed an attempt against a Citrix NetScaler Gateway on 24 September, three days before Citrix publicly disclosed CVE-2026-88771 and CVE-2026-88772, originating from 149.104.78.141; its platform detected the activity before any CVE-specific detections existed. GreyNoise says the attacker attempted to modify the appliance to give a root shell and to install a password-protected PHP web shell. CVE-2026-88771 is an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments, and CVE-2026-88772 is a memory overflow leading to code execution or denial of service when DTLS is enabled, which is the default on VPN virtual servers; researchers have dubbed the pair "PitScaler". Because exploitation predates the fix by weeks and involves root-level access, patching removes the vector but does not establish that an appliance was never compromised, and the update itself can destroy forensic visibility.

Attribute Detail
Sector Global (Macro)
Date 2026-09-30
Source BleepingComputer
Reliability Tier 2
CVEs CVE-2026-88771, CVE-2026-88772