NetScaler zero-day exploitation escalates into mass attacks
Exploitation of Citrix NetScaler ADC and Gateway flaws escalated into widespread attacks after a PoC for CVE-2026-88771 was published. Of roughly 42,000 exposed hosts, fewer than 10% are patched, and researchers track over 100 victim organizations.
- CVE-2026-88771 is remotely exploitable on unpatched devices with default configuration
- Censys: about 42,000 NetScaler hosts exposed online, 32% in the US
- Kevin Beaumont: fewer than 10% of exposed hosts patched, over 100 victims
- Attacks began September 24, before public disclosure of the flaw
Read next
Security