A widespread wave of exploitation is targeting vulnerable, internet-exposed Citrix NetScaler ADC and Gateway deployments after a proof-of-concept for CVE-2026-88771 was published. Researchers and vendors say attackers are using opportunistic scanning, log poisoning, and webshell deployment, with more than 100 victim organizations already being tracked. #Citrix #NetScalerADC #NetScalerGateway #CVE-2026-88771 #CVE-2026-88772
Keypoints
- Citrix NetScaler ADC and Gateway devices are being widely targeted on the internet.
- CVE-2026-88771 and CVE-2026-88772 were both exploited as zero-days.
- A public proof-of-concept for CVE-2026-88771 accelerated opportunistic attacks.
- Attackers are using log poisoning, webshells, and cleanup tactics to hide activity.
- Researchers believe fewer than 10% of exposed hosts are patched, with espionage as the likely goal.