NetScaler exploitation began days before public notification
Assessment
Cybersecurity Dive's 29 September headline was based on GreyNoise seeing an exploitation attempt on 24 September, three days before Citrix's 27 September bulletin. Later primary reporting pushed the start back by weeks: Mandiant told CyberScoop the earliest known CVE-2026-88772 exploitation was 3 September, Unit 42 recorded web shell requests from 4 September, and eSentire saw CVE-2026-88771 exploited and a web shell operated from 5 September. Cybersecurity Dive's own 30 September piece gives 'at least Sept. 3'. Days became three weeks.
Where this claim appeared
Cybersecurity Dive · 2026-09-29
https://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/What “Superseded” means
Reported accurately at the time, then corrected by the original source. Recorded because the original version usually continues circulating long after the correction.
2 of 5 · rating scale
Assessed in
Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772: three weeks of exploitation before the patchThink this assessment is wrong? Report an error.