ThreatPaper
Superseded

NetScaler exploitation began days before public notification

Assessment

Cybersecurity Dive's 29 September headline was based on GreyNoise seeing an exploitation attempt on 24 September, three days before Citrix's 27 September bulletin. Later primary reporting pushed the start back by weeks: Mandiant told CyberScoop the earliest known CVE-2026-88772 exploitation was 3 September, Unit 42 recorded web shell requests from 4 September, and eSentire saw CVE-2026-88771 exploited and a web shell operated from 5 September. Cybersecurity Dive's own 30 September piece gives 'at least Sept. 3'. Days became three weeks.

Where this claim appeared

Cybersecurity Dive · 2026-09-29

https://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/

What “Superseded” means

Reported accurately at the time, then corrected by the original source. Recorded because the original version usually continues circulating long after the correction.

2 of 5 · rating scale

Assessed in

Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772: three weeks of exploitation before the patch

Think this assessment is wrong? Report an error.