Back to advisories

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

NetScaler ADC and Gateway instances are being actively exploited via CVE-2026-88771 and CVE-2026-88772 to achieve root access and deploy web shells. Government and finance organizations have been targeted since early September, with attackers moving laterally post-compromise. State-sponsored actors are suspected.

CRITICALAdvisoryOct 02, 2026
Action required
Immediately identify and patch all NetScaler ADC and Gateway instances to the latest patched versions. If patching cannot be done within 24 hours, isolate affected devices from production networks and implement network segmentation to restrict lateral movement.
Affected products
NetScaler ADCNetScaler GatewayCitrixMandiantGoogle