Suspected State Hackers Exploited Citrix NetScaler for Weeks. 50,000 Devices May Still Be Exposed.
Two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, were used against organizations worldwide before a patch existed. CISA’s deadline is today. Patching alone will not tell you whether you were already breached. DataWater Threat Intelligence Desk | Published September 30, 2026 | 9-minute read Threat level: Critical What: Two unauthenticated remote-code-execution flaws in Citrix NetScaler ADC…
