More than 100 organizations already confirmed compromised
Assessment
The figure traces to Kevin Beaumont's Mastodon post of 28 September 2026, which says he is 'tracking over 100 victim orgs'. Beaumont has a strong record on edge-device incidents, but he published no method, no list and no definition of victim, and 'tracking' is not 'confirmed'. The vendors with incident-response visibility give smaller or vaguer numbers: Mandiant says 'dozens of impacted organizations', Rapid7 confirms two among its customers, and Arctic Wolf (via Cybersecurity Dive) says at least 78 were targeted. No affected organisation has been publicly named.
Where this claim appeared
Tech Times · 2026-09-30
https://www.techtimes.com/articles/328303/20260930/citrix-netscaler-zero-days-spread-mass-exploitation-patching-wont-remove-backdoors.htmWhat “Weak Evidence” means
Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.
3 of 5 · rating scale
Assessed in
Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772: three weeks of exploitation before the patchThink this assessment is wrong? Report an error.