"We are aware of dozens of impacted organizations," Charles Carmakal, chief technology officer at Mandiant Consulting, wrote in a LinkedIn post.
That admission underscores the scale and stealth of a recent campaign in which attackers exploited a critical zero‑day vulnerability in Citrix NetScaler appliances for at least three weeks before researchers confirmed active exploitation. Mandiant told CyberScoop the earliest known instance of CVE‑2026‑88772 exploitation occurred Sept. 3; investigators only publicly confirmed in‑the‑wild attacks late the following week. By that point, the firm says, organizations across North America and Europe — spanning government, financial services, education, telecom, legal and professional services — were already likely compromised.
CVE‑2026‑88772 exploitation timeline and scale
Mandiant’s public timeline places the first observed exploitation of CVE‑2026‑88772 on Sept. 3, with attackers remaining undetected for "more than three weeks," the company told CyberScoop. Mandiant researchers emphasized the gap between initial exploitation and public confirmation gave attackers a significant operational advantage and warned that the interval "could be even wider" as they continue to respond to active intrusions. The firm said it is still responding to incidents and that "new evidence may change our understanding of the campaign timeline."
CVE‑2026‑88771: a second zero‑day and parallel campaigns
The NetScaler incident involved more than a single defect. GreyNoise reported attackers had exploited a second Citrix NetScaler zero‑day, CVE‑2026‑88771, "since at least Sept. 24," although GreyNoise and Mandiant both noted that the CVE‑2026‑88771 campaign likely began earlier than that date. The two zero‑days may not be linked; researchers described the situation as attacks "from multiple fronts" that together created an "alarming and sustained pattern of malicious activity" against edge devices. Citrix disclosed both actively exploited defects in a security advisory on Sunday, releasing patches for those vulnerabilities along with six additional fixes.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildMandiant observed novel tools, tunneler malware, and credential theft
Mandiant’s analysis found attackers using multiple novel tools and techniques to turn initial NetScaler exploitation into privileged access, lateral movement and data exfiltration. In one observed intrusion, a threat actor "routed traffic through novel tunneler malware to manually conduct internal reconnaissance and credential theft," researchers wrote. The company also attributed the activity to "advanced and suspected state‑sponsored threat actors" in Charles Carmakal’s LinkedIn post. Separately, researchers at watchTowr published technical analysis of CVE‑2026‑88782 on Tuesday, adding additional public detail about the set of NetScaler vulnerabilities under scrutiny.
Edge devices, visibility gaps, and why attackers prioritized NetScaler
Mandiant links the attacks against Citrix NetScaler to a wider pattern: threat actors prioritize edge devices because these appliances frequently sit at network perimeters and often lack standard endpoint detection and response (EDR) coverage. The company wrote that "most edge devices do not support endpoint detection and response (EDR) monitoring," and that exploiting zero‑days in such devices gives attackers an infection vector "that is difficult to detect and prevent, and the opportunity to scale a campaign as long as the exploit remains undiscovered." That finding echoes a statistic from Google Threat Intelligence Group cited by Mandiant: vulnerabilities in edge devices accounted for 48% of enterprise‑related zero‑days last year.
What this means for government, financial services, and education
- Government: Agencies in North America and Europe were listed among likely compromised organizations; they will be wrestling with incident response while Mandiant continues active remediation and timeline refinement.
- Financial services: Banks and financial institutions are named among the sectors likely affected and face the dual tasks of applying Citrix’s patches and investigating potential credential theft and lateral movement tied to tunneler malware.
- Education: Schools and universities, also identified by Mandiant, must evaluate exposure on perimeter appliances and contend with detection blind spots that make early compromise harder to spot.
Charles Carmakal warned on LinkedIn that Mandiant expects "broad and opportunistic exploitation" of both NetScaler zero‑days by a variety of threat actors in the near term — a forecast that makes rapid patching and active intrusion hunting urgent priorities for the named sectors.
The incident underscores two clear facts: attackers moved early and, for weeks, largely unseen; and defenders continue to chase the full picture as Mandiant responds to active intrusions and additional analysis — from GreyNoise, watchTowr and others — refines when and how multiple NetScaler vulnerabilities were exploited. The immediate next step is straightforward and onerous: apply the Citrix patches issued in the security advisory and assume incident response is still underway while investigators update the timeline.
Read the original CyberScoop story: https://cyberscoop.com/citrix-netscaler-zero-day-attacks-three-weeks-undetected/




