Mass Exploitation of Citrix NetScaler Hits Dozens of Organisations Across Europe and North America
Suspected state-linked threat actors are actively exploiting two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, causing widespread disruption across dozens of organisations in Europe and North America. The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, both carry severity scores of 9.5 out of 10.
CVE-2026-88771 is a remote code execution vulnerability stemming from improper input validation. It allows an attacker to execute arbitrary commands on an affected system without authentication, and it impacts all versions of NetScaler ADC and Gateway, even in default configurations. CVE-2026-88772 is a memory overflow vulnerability that can also lead to remote code execution or denial of service, though successful exploitation requires DTLS to be enabled — a protocol that is on by default for VPN virtual servers.
Citrix disclosed a total of eight vulnerabilities on Sunday, with these two confirmed under active exploitation. Arctic Wolf has published details of post-exploitation activity including the use of Python, Perl and shell scripts on compromised appliances, as well as reverse-shell attempts that give attackers persistent remote access.
Persistence is the central concern. If backdoor mechanisms survive patching or partial cleanup, organisations face continued unauthorised access even after they believe the original vulnerability has been addressed. Citrix has released patches and urged all customers to update immediately, but the scale of exploitation suggests many appliances remain unpatched.
Source: Cybersecurity Dive. This article summarizes the linked reporting and distinguishes announced plans from demonstrated results.