CyberScoop reported on 29 September 2026 that attackers exploited a flaw in Citrix NetScaler appliances for at least three weeks before it was confirmed, with the earliest known exploitation on 3 September. Mandiant attributes the campaign to advanced and suspected state-sponsored actors, and Citrix released patches on Sunday 28 September for both flaws and six further defects [1] [3]. The reports concern organisations, but the same gateways front small offices and remote workers.
Background
NetScaler ADC and NetScaler Gateway are appliances that sit at the edge of a network and handle remote access and traffic delivery, so they are reachable from the internet by design. CyberScoop notes that edge devices made up 48 per cent of enterprise attacks of this kind last year, and that they typically lack endpoint detection monitoring [1]. An office that reaches its files or applications through a NetScaler VPN, whether it runs the appliance or a provider runs it on its behalf, depends on that device being patched.
Findings
Two flaws are named, CVE-2026-88772 and CVE-2026-88771. CyberScoop describes the second as a command-injection vulnerability and reports that both are rated 9.5 on the CVSS scale and allow remote code execution on NetScaler ADC and Gateway devices in default configurations [2]. watchTowr's analysis of CVE-2026-88772 describes a memory overflow in the handling of fragmented DTLS handshake messages. DTLS is enabled by default for VPN virtual servers, and an administrator has to have switched it off explicitly to avoid exposure [4].
According to CyberScoop, GreyNoise saw an unsuccessful exploitation attempt on 24 September, and warnings circulated through unofficial channels over the weekend while Citrix was publicly silent; Citrix published its advisory on Sunday 28 September [2]. watchTowr's chief executive Ben Harris is quoted as saying that customers were receiving warnings through unofficial channels in that period [2].
Mandiant describes an attack chain in which malformed DTLS record headers lead to heap memory corruption and code execution with root privileges. After that, the attackers set up persistence in the appliance's web server configuration and deployed two tools Mandiant names WHIPSHOT, a PHP web shell, and SLAPSHOT, a Python proxy used to tunnel traffic [3]. CyberScoop adds that Mandiant's Charles Carmakal said Mandiant is aware of dozens of impacted organisations and expects broad and opportunistic exploitation in the near term. The affected sectors include government, financial services, education, telecommunications, legal and professional services in North America and Europe [1].
CyberScoop reports that Palo Alto Networks identified more than 50,000 publicly exposed vulnerable instances as of Sunday, and that CISA added both flaws to its catalogue of known exploited vulnerabilities. It was the fifth Citrix entry in 2026 and the 26th since late 2021 [2].
Implications for small offices and remote workers
The vulnerable component is the appliance, not the laptop behind it. A person who connects through a NetScaler gateway cannot patch it, and cannot tell from the client side whether it has been updated. Mandiant lists credentials stored on or passing through the appliance among the items to rotate after a compromise, including LDAP bind accounts, RADIUS shared secrets and TACACS credentials, and advises auditing downstream infrastructure such as StoreFront and Virtual Apps hosts [3]. For a small office, that translates into questions for whoever operates the gateway.
Recommendations
- Ask the operator of the gateway, the IT provider or the employer's IT team, whether it runs NetScaler and which build. The fixed builds named by Mandiant and watchTowr are 14.1-73.37 and 13.1-64.23 or later, including their FIPS variants [3] [4].
- Where patching is delayed, Mandiant lists compensating controls: disabling DTLS where feasible, blocking inbound UDP 443 upstream, and allow-listing source addresses on the perimeter firewall [3].
- After a suspected compromise, revoke active admin and VPN sessions and rotate the appliance's credentials and SSH keys [3].
- Treat passwords used through the gateway since early September as potentially exposed if the operator cannot confirm a clean appliance, and change them [3].
- Do not rely on the absence of alerts. The campaign ran for at least three weeks before it was confirmed [1].
Relevance to FireAI
FireAI runs on a Mac. It does not patch, scan or monitor a NetScaler appliance, cannot see traffic to or inside the gateway beyond what the Mac itself sends, and does not detect an intrusion on a network device. What it does is local. Activity and connection history shows which app connected to which server, so an unexpected app contacting a new destination is visible. Rules can allow the VPN client to reach the office gateway and nothing else. If a person suspects that an account used from a Mac has been exposed, the kill switch refuses new connections outside the home or office network, though it does not close connections that are already open.
Limitations
The two CyberScoop articles are secondary reporting, and the details that differ between them, such as the exact date on which the attacks were confirmed, were not reconciled. The Palo Alto Networks figure of 50,000 exposed instances is quoted by CyberScoop; the Unit 42 threat brief itself could not be retrieved for this item. The sources do not say how many small offices are affected, whether any victim was a Mac user, or who the actors are beyond Mandiant's description. The 48 per cent figure refers to enterprise attacks of this kind in the previous year as stated by CyberScoop and was not checked against the underlying study.
Try FireAI, by HisnLabs free for 17 days.