[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:government-finance-orgs-targeted-in-weeks-long-netscaler-zero-day-attacks-muqqn4rf":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":14,"action_required":20,"article_ids":21,"ioc_summary":23,"source_urls":24,"status":26,"expires_at":27,"created_at":28,"updated_at":29,"articles":30},"07455914-b305-4dab-8315-a0a74fd7f70a","Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks","government-finance-orgs-targeted-in-weeks-long-netscaler-zero-day-attacks-muqqn4rf","NetScaler ADC and Gateway instances are being actively exploited via CVE-2026-88771 and CVE-2026-88772 to achieve root access and deploy web shells. Government and finance organizations have been targeted since early September, with attackers moving laterally post-compromise. State-sponsored actors are suspected.","critical","advisory",[12,13],"CVE-2026-88771","CVE-2026-88772",[15,16,17,18,19],"NetScaler ADC","NetScaler Gateway","Citrix","Mandiant","Google","Immediately identify and patch all NetScaler ADC and Gateway instances to the latest patched versions. If patching cannot be done within 24 hours, isolate affected devices from production networks and implement network segmentation to restrict lateral movement.",[22],"4463a00f-8eeb-46a6-b408-eac0a22e4f9e",null,[25],"https:\u002F\u002Fwww.securityweek.com\u002Fgovernment-finance-orgs-targeted-in-weeks-long-netscaler-zero-day-attacks\u002F","active","2026-10-04T09:05:43.814+00:00","2026-10-02T09:05:50.186996+00:00","2026-10-02T09:15:04.865837+00:00",[31],{"id":22,"title":6,"url":25}]