Citrix NetScaler zero-day timeline, September 2026

Times are UTC unless marked otherwise.

  1. Research

    eSentire: CVE-2026-88771 exploited as early as 5 September

    eSentire TRU incident response saw exploitation of Internet-facing NetScaler Gateways from 5 Sep, more than three weeks before disclosure: base64 PHP staged in the access log via fake /vpn/media/*.ico requests, then executed through a crafted login username. In one intrusion a .deb-variant webshell was installed and operated from 5 Sep, with signs of data exfiltration and lateral movement to internal virtual desktops and back to the appliance over SSH.

    Sources: [32]

  2. Official advisory Validated

    CVE IDs reserved

    NetScaler reserves CVE-2026-88771 and CVE-2026-88772 at 07:14 UTC. The records were published on 27 Sep at 16:02 and 16:09 UTC.

    Validated against the CVE record on 29 Sep.

    Sources: [18][37]

  3. Reported observation

    Danish NetScalers start going offline

    Ingeniøren's review of Shodan data shows several Danish NetScaler systems switched off from 23 Sep, four days before Citrix's public disclosure.

    Sources: [66]

  4. Telemetry

    GreyNoise sensors see exploitation from a single IP

    149.104.78.141: 3 sessions 07:32:19-07:32:20 UTC. IP flagged "suspicious" (Citrix ADC Gateway Login Panel Crawler), then "malicious" (Generic ${IFS} Use in RCE Attempt; CitrixBleed 2 attempt). Later retro-tagged as CVE-2026-88771. GreyNoise's retro-hunt found no other exploitation sessions before disclosure - this covers GreyNoise sensors only.

    Sources: [36][37][38]

  5. Reported observation Validated

    Danish government agencies shut down their NetScalers

    Danish agencies, among them PET, the Armed Forces and the police, took their Citrix NetScaler environments offline from Friday 25 Sep, two days before Citrix disclosed the vulnerabilities. Ingeniøren later reported the shutdowns from Shodan data; none of the agencies would explain why.

    The Friday 25 Sep shutdown was validated independently on 30 Sep.

    Sources: [66]

  6. Official advisory

    NCSC-NL confidentially warns Dutch organisations

    On the afternoon of Friday 25 Sep, after a tip from a European partner, NCSC-NL confidentially informed companies and organisations, including central government, about two NetScaler zero-days being exploited outside the Netherlands, before any patch existed. Dark Reading reports that a copy of the pre-notification, marked TLP:AMBER+STRICT, was briefly posted on Reddit and then deleted. According to BleepingComputer, the notice said Citrix found the vulnerabilities while investigating incidents at customers and filed a notification under the EU Cyber Resilience Act.

    Sources: [17][70][55]

  7. Reported observation Validated

    r/Citrix "Netscaler leak?" thread

    User FastFredNL opens the thread at 06:43:22 UTC (08:43 CEST), reporting that an IT provider advised shutting NetScalers down immediately. It becomes the first public gathering point, with admins reporting similar unofficial advice over the weekend. Dark Reading dates the first reports to 25 Sep, but the thread itself was posted on 26 Sep.

    Post timestamp checked on the thread itself (30 Sep). The shutdown advice is consistent with the Dutch government letter to parliament.

    Sources: [73][40][70][17]

  8. Research

    watchTowr: two unpatched RCE zero-days, found during forensics

    Two vulnerabilities - both RCE. Unpatched, 0days. Exploited in-the-wild - discovered during forensics.

    watchTowr adds that Citrix comms and patches are expected early the following week.

    Sources: [34]

  9. Reported observation

    IFIN opens a public tracking thread

    IFIN starts compiling public reporting and observables for the NetScaler zero-days; it later states that all observables it shares were shared without restriction.

    Sources: [40]

  10. Reported observation

    watchTowr: pull NetScaler appliances offline immediately

    Please, take this seriously and pull NetScaler appliances offline immediately.

    watchTowr publicly warns that credible rumours of unpatched NetScaler RCEs are circulating; later that day CEO Benjamin Harris says the rumours are confirmed and urges admins to pull NetScaler appliances offline immediately.

    Sources: [70]

  11. Reported observation

    Dutch hospitals Amphia and ETZ close patient portals

    Patients of Amphia (Breda) and Elisabeth-TweeSteden Ziekenhuis (Tilburg) cannot log in to their portals; other Dutch hospitals report problems too. That evening Z-CERT, the Dutch healthcare CERT, says it warned the sector about critical vulnerabilities in Citrix NetScaler and advised temporarily switching the system off.

    Sources: [71]

  12. Official advisory

    Public disclosure; Citrix publishes CTX697096 with fixes

    Disclosure time per GreyNoise. The bulletin covers 8 CVEs. watchTowr notes the patch it analysed was dated 24 Sep, suggesting Citrix knew of the exploitation the week before.

    Sources: [1][37][70]

  13. Official advisory

    Citrix announces the bulletin on r/Citrix

    A Citrix staff account (CTX-Michael) posts a CRITICAL UPDATE in r/Citrix linking the CTX697096 bulletin and the Citrix community blog post with its IoC section, and quoting that exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated deployments has been observed.

    Sources: [3][2]

  14. Telemetry

    GreyNoise deploys CVE-specific tag

    Tag deployed 20:28:39 UTC; the 24 Sep sessions are retro-tagged as CVE-2026-88771.

    Sources: [37][39]

  15. Official advisory Validated

    CISA adds CVE-2026-88771 and CVE-2026-88772 to KEV

    Both were added on 27 Sep with a federal remediation deadline of 30 Sep. The 21:30 UTC release time comes from the compiled dataset and was not found in the sources checked.

    Dates validated against the KEV catalog feed on 29 Sep.

    Sources: [5][12]

  16. Telemetry

    Unit 42: 50,277 exposed instances

    Palo Alto Networks Cortex Xpanse identifies 50,277 exposed NetScaler instances that could potentially be vulnerable (update posted 4:15 p.m. PT). Exposure, not confirmed compromise.

    Sources: [63]

  17. Official advisory

    Danish Defence Intelligence (FE) and CERT-EU warn NetScaler users

    The Danish Defence Intelligence Service sent a warning urging NetScaler users to update, per Ingeniøren. CERT-EU published Security Advisory 2026-014 recommending an immediate update of all customer-managed appliances and enabling Enhanced ISN Generation where TCP is configured.

    Sources: [66][13]

  18. Reported observation

    Beaumont: three CVEs chained, webshells all September

    The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained. It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September. Probably nation state aligned

    Beaumont's claim; attribution not independently verified.

    Sources: [44]

  19. Reported observation

    Beaumont: patches live, detection script behind NDA

    patching alone doesn't remove the backdoors being placed

    Patches are live on the main support site; Citrix's detection script is locked behind NDA/support.

    Sources: [45]

  20. Reported observation Validated

    Beaumont: Console check misses earlier attempts

    The NetScaler Console check misses earlier semi-successful attempts because it relies on logs not having rotated; he adds that the activity is weeks old because of slow disclosure.

    Validated independently on 29 Sep.

    Sources: [46]

  21. Official advisory

    NHS England alert CC-4858

    NHS England's National CSOC rates the threat High and assesses further exploitation as almost certain. It strongly recommends a compromise assessment before patching, since patching first may delete evidence, and warns that end-of-life 12.1 and 13.0 releases are likely vulnerable and receive no fix. Published 10:40 UK time.

    Sources: [15]

  22. Reported observation

    Beaumont names it "PitScaler"

    I'm tracking over 100 victim orgs now. Each one has a unique webshell which can't be scanned for remotely unless you're the attacker. It's espionage.

    Victim count is Beaumont's claim, not independently verified.

    Sources: [47]

  23. Reported observation Validated

    Beaumont: Citrix checker incomplete

    Some really big orgs are backdoored after patching still

    The checker does not check for suid on /bin/sh; Beaumont calls on NCSCs to publish a detection script.

    The missing suid /bin/sh check was validated independently on 29 Sep. The claim about big organisations still being backdoored is not independently verified.

    Sources: [48]

  24. Reported observation

    Press covers the weekend shutdown warnings

    BleepingComputer, SecurityWeek, The Record and CyberScoop cover the story.

    Sources: [55][56][57][58]

  25. Research

    CERT-EU technical writeup on CVE-2026-88771

    "Taking 'execute logging' a bit too literally" - root cause, attack chain and hunting guidance.

    Sources: [19]

  26. Official advisory

    Government advisories worldwide

    NCSC-NL NCSC-2026-0394 [H/H], NCSC-UK, CSA Singapore AL-2026-129, plus Canada, HKCERT, ACSC, and CIRCL TR-100 with per-CVE config-check CLI commands.

    Sources: [6][7][8][9][10][11][16]

  27. Telemetry

    GreyNoise publishes TLP:CLEAR IoC set

    "Swarming Against Citrix 0-Day Exploitation" - the first public IoC set in this compiled dataset as of 29 Sep, with a companion Chronicle timeline.

    Sources: [36][37]

  28. Research

    watchTowr Labs part 1 (CVE-2026-88771)

    "Oh Look, the Foot Gun Went Off Again", published with a Detection Artefact Generator (PoC-class tool).

    Sources: [20][21]

  29. Telemetry

    Censys and Shadowserver count exposed NetScalers

    Censys detects NetScaler ADC or Gateway on 42,735 hosts and 323,527 web properties; these are exposed instances, not confirmed-vulnerable counts. Shadowserver reports more than 20,000 instances exposed and potentially at risk.

    Sources: [41][64]

  30. Telemetry

    Lupovis honeypots see exploitation minutes after the public PoC

    Lupovis says its sensors recorded live CVE-2026-88771 exploitation attempts within minutes of watchTowr releasing its PoC; the attempts were opportunistic, from several distinct actors.

    Sources: [65][27]

  31. Research

    First public detection rules

    Elastic merges a rule for NetScaler log-poisoning command injection; Corelight publishes Zeek hunting queries. Sigma and Nuclei pull requests follow (28-29 Sep, still unmerged at snapshot time).

    Sources: [29][28][30][31]

  32. Research

    Truesec publishes potential C2 IPs

    Truesec lists 104.248.244.66, 139.180.152.138 and 77.83.199.39 as potential C2 IPs it has observed.

    Sources: [24]

  33. Official advisory

    ACSC alert; Australian organisations later confirm exploitation

    Australia's ACSC publishes an alert on 28 Sep. In an update it says Australian organisations have since confirmed exploitation, and recommends reviewing for evidence of compromise since at least 4 Sep 2026.

    Sources: [11]

  34. Reported observation

    Dutch ministry and hospitals take systems offline

    The Dutch Ministry of the Interior took all Citrix environments offline over the weekend; patients of two major hospitals (Amphia and ETZ) could not view their records, and Frisius MC in Leeuwarden shut down some digital systems as a precaution (SDxCentral, citing Techzine).

    Sources: [67]

  35. Reported observation

    Beaumont: mass exploitation

    #PitScaler is under mass exploitation, seeing it spray and pray now. I've done some firmware version scanning, fewer than 10% of boxes are patched

    The <10% figure is Beaumont's own estimate, not independently verified.

    Sources: [49]

  36. Reported observation Compromise unverified

    Beaumont posts a public message to the NSA

    do forensics on 103.41.70.207,vdicorp.nsa.gov

    The domain resolves to that IP. That the host is an NSA-operated Citrix system has been validated independently. That it is compromised is Beaumont's implication and is not verified. This briefing does not identify any organisation as compromised, and these values are not listed as IoCs.

    Sources: [50]

  37. Reported observation Validated

    Beaumont: IR writeups expose victim-unique indicators

    IR vendors are publishing PitScaler writeups containing victim-unique webshell names (.sig files) and attacker IPs, which he says lets him map victim orgs via network traffic. He warns that unremediated orgs' published webshell names can be used to access their boxes, and says one vendor uploaded its IR investigation to VirusTotal.

    Validated independently on 29 Sep.

    Sources: [51]

  38. Reported observation

    The Register: government, banks and professional services targeted

    Why Citrix took so long to disclose these vulnerabilities is a question only Citrix can answer

    It reports GTIG/Mandiant findings that government, financial services, education and legal and professional services organisations in North America and Europe were likely hit. watchTowr CEO Benjamin Harris criticises the slow disclosure and says no attribution has been made public.

    Sources: [62][25]

  39. Research

    watchTowr Labs part 2 (CVE-2026-88772)

    "Here We Go Again" (Sina Kheirkhah) - full RCE analysis plus a second Detection Artefact Generator.

    Sources: [22][23]

  40. Research

    Google GTIG / Mandiant: custom malware WHIPSHOT and SLAPSHOT

    The CVE-2026-88772 campaign has been ongoing since at least early September. WHIPSHOT is a PHP webshell staged with a .deb disguise that hides base64 C2 in HTTP headers; SLAPSHOT is a Python TCP tunneler (open/push/pull/exch/close/ping) used to reach internal networks for reconnaissance and credential theft.

    Sources: [25][62]

  41. Reported observation

    BleepingComputer: credential theft and internal spread

    It reports that attackers exploited CVE-2026-88772 to deploy webshells and tunneling malware, gain root, steal credentials and spread into internal networks, citing Mandiant. GTIG itself describes the credential theft and internal reconnaissance in at least one observed intrusion.

    Sources: [54][25]

  42. Reported observation Validated

    Mandiant CTO: check for compromise before patching

    Given the active exploitation, NetScaler customers should prioritize examining their systems for compromise *before* upgrading/patching

    Charles Carmakal on LinkedIn, as quoted by The Register.

    Quote validated against a second, non-public source on 29 Sep.

    Sources: [62]

  43. Research

    Nextron releases THOR rules and a NetScaler filesystem IoC set

    Three rules in the THOR Preview channel (higher false-positive rate than stable rules) plus a YAML IoC set derived from the filesystem checks in Citrix's scanner script. A match is a lead, not proof.

    Sources: [26]

  44. Research

    eSentire publishes first-hand IR findings and IoCs

    Two webshell variants (.ico and .deb), 14 IPs and 2 SHA-256 hashes; the technique matches CERT-EU's description. eSentire advises treating appliances that were Internet-facing and unpatched in early September as potentially compromised until an integrity assessment shows otherwise.

    Sources: [32]

  45. Telemetry

    Defused: hundreds of decoy hits across multiple exploit paths

    Defused reports hundreds of CVE-2026-88771 hits on its decoys in 24 hours via /nf/auth/doAuthentication.do, /cgi/login, /p/u/doLogon.do, /logon/LogonPoint/tmindex.html and User-Agent payloads on /. Observed follow-up: whoami/id to prove root, nx_verify.html marker files, curl/wget/fetch pulling a second stage, and blind DNS callbacks. Full IoCs are on Defused Radar (not reproduced here).

    Sources: [42]

  46. Official advisory

    DKCERT warns Danish universities and research institutions

    DKCERT, the CERT for the Danish research and education network, reports two critical NetScaler zero-days exploited before a patch and notes that several administrators took systems offline before Citrix published details.

    Sources: [14]

  47. Reported observation

    Mandiant: dozens of organisations impacted

    Cybersecurity Dive reports Mandiant CTO Charles Carmakal saying the actor deployed webshells and moved laterally into internal networks at some targets, with dozens of organisations impacted across North America and Europe, including telecommunications.

    Sources: [68]

  48. Official advisory

    Dutch government confirms preventive disconnection

    Letter to parliament: on Saturday 26 Sep the CIO Rijk set the line "loskoppelen tenzij" (disconnect unless) for central government, and it was broadly applied; remote-work access has not yet been restored everywhere while the patch is tested and forensic investigation continues. Beaumont relays it at 18:32 UTC as "shut down all Citrix Netscalers".

    Sources: [17][53]

  49. Reported observation

    Ingeniøren: PET, Danish Defence and police shut down Citrix

    Based on Shodan data, Ingeniøren reports that PET, the Danish Armed Forces, the Danish police and Copenhagen Airport, among many others, had to switch off their Citrix environments over the weekend. None of the agencies would explain why.

    Sources: [66]

  50. Official advisory Deadline - upcoming

    Deadline: CISA KEV federal remediation

    Due on the snapshot date (30 Sep). A deadline, not an event.

    Sources: [5]

Related pages

References

#SourceTypeURL
1Citrix - CTX697096 security bulletin (Sep 27)Primary official advisorieshttps://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
2Citrix community blog - Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (incl. IoC section) verification pendingPrimary official advisorieshttps://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/
3Citrix (CTX-Michael) on r/Citrix, Sep 27 - CRITICAL UPDATE announcementPrimary official advisorieshttps://www.reddit.com/r/Citrix/comments/1wro1yf/critical_update_citrix_netscaler_adc_and_citrix/
4NetScaler Console documentation - Indicators of Compromise detection (incl. Citrix disclaimer on limits)Primary official advisorieshttps://docs.netscaler.com/en-us/netscaler-console-service/instance-advisory/ioc
5CISA alert - Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC/Gateway (Sep 27)Primary official advisorieshttps://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
6NCSC-NL advisory NCSC-2026-0394 (probability high, damage high; per-CVE scores and preconditions)Primary official advisorieshttps://advisories.ncsc.nl/
7NCSC-UK - Exploitation of vulnerabilities affecting Citrix NetScaler ADC and GatewayPrimary official advisorieshttps://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
8CSA Singapore - AL-2026-129Primary official advisorieshttps://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-129/
9Canadian Centre for Cyber Security - AL26-024Primary official advisorieshttps://www.cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772
10HKCERT - Citrix Products Multiple Vulnerabilities (Sep 28)Primary official advisorieshttps://www.hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928
11ACSC (Australia) - Critical vulnerabilities in Citrix NetScaler ADC and NetScaler GatewayPrimary official advisorieshttps://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products
12CISA Known Exploited Vulnerabilities catalog (both CVEs added Sep 27, due Sep 30)Primary official advisorieshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
13CERT-EU Security Advisory 2026-014 - Critical Vulnerabilities in Citrix NetScaler ADC and Gateway (Sep 27)Primary official advisorieshttps://cert.europa.eu/publications/security-advisories/2026-014/
14DKCERT (CERT for Danish universities and research) - To kritiske NetScaler 0-dage udnyttes aktivt før patch (Sep 29)Primary official advisorieshttps://cert.dk/node/639
15NHS England Digital cyber alert CC-4858 (Sep 28) - Exploitation of zero-day vulnerabilities affecting Citrix NetScalerPrimary official advisorieshttps://digital.nhs.uk/cyber-alerts/2026/cc-4858
16CIRCL TR-100 - per-CVE configuration-check CLI commandsPrimary official advisorieshttps://www.circl.lu/pub/tr-100/
17Dutch government letter to parliament - Kwetsbaarheden Citrix Netscaler (2026D47262, Sep 29)Primary official advisorieshttps://www.tweedekamer.nl/kamerstukken/brieven_regering/detail?id=2026D47262&did=2026D47262
18CVE.org - CVE-2026-88771 record (reserved Sep 10 07:14 UTC by NetScaler; published Sep 27 16:02 UTC)Primary official advisorieshttps://www.cve.org/CVERecord?id=CVE-2026-88771
19CERT-EU - Taking "execute logging" a bit too literally - CVE-2026-88771 (Sep 28)Technical researchhttps://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771
20watchTowr Labs part 1 - Oh Look, the Foot Gun Went Off Again (CVE-2026-88771) (Sep 28)Technical researchhttps://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/
21watchTowr Detection Artefact Generator - CVE-2026-88771 (GitHub)Technical researchhttps://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771
22watchTowr Labs part 2 - Here We Go Again (CVE-2026-88772), Sina Kheirkhah (Sep 29)Technical researchhttps://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/
23watchTowr Detection Artefact Generator - CVE-2026-88772 (GitHub)Technical researchhttps://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772
24Truesec - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (Sep 28)Technical researchhttps://www.truesec.com/hub/blog/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway
25Google GTIG / Mandiant - Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances (Sep 29)Technical researchhttps://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances
26Nextron Systems (Florian Roth) - New THOR Detection Coverage for CVE-2026-88771 and CVE-2026-88772 (Sep 29)Technical researchhttps://www.nextron-systems.com/2026/09/29/new-thor-detection-coverage-for-citrix-netscaler-cve-2026-88771-and-cve-2026-88772/
27Beazley Security advisory (updated Sep 29) - IoC table incl. Lupovis honeypot IPsTechnical researchhttps://beazley.security/alerts-advisories/critical-vulnerability-in-citrix-netscaler-zero-day-prompts-emergency-shutdowns-cve-2026-88771-cve-2026-88772
28Corelight - Hunting Citrix NetScaler zero-days (Zeek queries, Sep 28)Technical researchhttps://corelight.com/blog/hunting-citrix-netscaler-zero-days-corelight
29Elastic detection rule - Potential NetScaler Log Poisoning Command Injection Attempt (merged Sep 28)Technical researchhttps://github.com/elastic/detection-rules/blob/main/rules/network/initial_access_netscaler_log_poisoning_command_injection.toml
30SigmaHQ pull request #6352 - NetScaler auth endpoint shell metacharacters (open, Sep 29)Technical researchhttps://github.com/SigmaHQ/sigma/pull/6352
31Nuclei templates pull request #17336 - CVE-2026-88771 active probe (open, Sep 28)Technical researchhttps://github.com/projectdiscovery/nuclei-templates/pull/17336
32eSentire TRU - Update: ongoing exploitation of NetScaler CVE-2026-88771 / -88772 (first-hand IR, Sep 29)Technical researchhttps://www.esentire.com/security-advisories/update-ongoing-exploitation-of-citrix-netscaler-adc-and-netscaler-gateway-vulnerabilities-cve-2026-88771-cve-2026-88772
33Beazley Security Labs - BSL-A1216 advisory (updates 3-4, Sep 29): consolidated IoCs and hunting commandsTechnical researchhttps://labs.beazley.security/advisories/BSL-A1216
34watchTowr (@watchtowrcyber) on X, Sep 26 - "Unpatched, 0days. Exploited in-the-wild - discovered during forensics."Technical researchhttps://x.com/watchtowrcyber/status/2103972792043479307
35CyberMaxx - Patches required: Citrix NetScaler vulns exploited in the wild (IoC notes)Technical researchhttps://www.cybermaxx.com/resources/patches-required-citrix-netscaler-vulns-exploited-in-the-wild-cve-2026-88771-and-cve-2026-88772/
36GreyNoise - Swarming Against Citrix 0-Day Exploitation (TLP:CLEAR IoCs, Sep 28)Telemetry and IoCshttps://greynoise.io/blog/swarming-against-citrix-0-day-exploitation
37GreyNoise Chronicle - GNTL-20260928 CVE-2026-88771 timelineTelemetry and IoCshttps://www.greynoise.io/chronicle/gntl-20260928-citrix-cve-2026-88771
38GreyNoise Visualizer - IP 149.104.78.141Telemetry and IoCshttps://viz.greynoise.io/ip/149.104.78.141
39GreyNoise tag - Citrix NetScaler CVE-2026-88771 Login Command Injection RCE AttemptTelemetry and IoCshttps://viz.greynoise.io/tag/citrix-netscaler-cve-2026-88771-login-command-injection-rce-attempt
40IFIN - Multiple Citrix Netscaler 0-Days Exploited (tracking thread, from Sep 26; observables "shared without restriction")Telemetry and IoCshttps://ifin.network/t/multiple-citrix-netscaler-0-days-exploited/867
41Censys advisory - NetScaler exposure (42,735 hosts, Sep 28)Telemetry and IoCshttps://censys.com/advisory/cve-2026-10747-2/
42Defused (@DefusedCyber) on X, Sep 29 - decoy hits across multiple CVE-2026-88771 pathsTelemetry and IoCshttps://x.com/DefusedCyber/status/2104888497693708505
43Lupovis (@LupovisDefence) on X, Sep 28 - decoys catch CVE-2026-88771 exploitation hours after the PoCTelemetry and IoCshttps://x.com/lupovisdefence/status/2104595071362326680
44Beaumont, Sep 27 - chained CVEs, webshells all September, "Probably nation state aligned"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117343729453093307
45Beaumont, Sep 27 - patches live; detection script behind NDA; patching does not remove backdoorsKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117343821114841048
46Beaumont, Sep 27 - Console check misses attempts when logs have rotatedKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117345540231975640
47Beaumont, Sep 28 22:49 UTC - names "PitScaler", >100 victim orgs (his claim)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117351107654208046
48Beaumont, Sep 28 23:02 UTC - Citrix checker incomplete (suid /bin/sh)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117351155381900219
49Beaumont, Sep 29 04:39 UTC - mass exploitation, <10% patched (his claim)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117352481501981552
50Beaumont, Sep 29 06:18 UTC - public message to the NSA (his unverified claim)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117352869498139711
51Beaumont, Sep 29 16:12 UTC - IR vendors publishing victim-unique webshell namesKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117355208096613386
52Beaumont, Sep 28 15:13 UTC - GitHub "PoCs" for the new Citrix vulns are "fake AI slop"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117349313638958333
53Beaumont, Sep 29 18:32 UTC - Dutch government shuts down all Citrix NetScalers (relaying @bert_hubert)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117355758746619146
54BleepingComputer (Sep 29) - Hackers exploit Citrix NetScaler zero-day to deploy web shellsPress and vendor coveragehttps://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/
55BleepingComputer (Sep 27) - Citrix admins warned to shut down NetScalersPress and vendor coveragehttps://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
56SecurityWeek (Sep 28) - Citrix confirms 2 NetScaler zero-daysPress and vendor coveragehttps://www.securityweek.com/citrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug/
57The Record (Sep 28) - US, UK warn of Citrix NetScaler zero-day bugPress and vendor coveragehttps://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug
58CyberScoop (Sep 28) - delayed-disclosure anglePress and vendor coveragehttps://cyberscoop.com/citrix-zero-days-delayed-disclosure/
59Sophos CTU (Sep 28) - CVE-2026-88771 / -88772 in active exploitationPress and vendor coveragehttps://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation
60Rapid7 ETR (Sep 28)Press and vendor coveragehttps://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/
61watchTowr FAQ (Sep 27-28)Press and vendor coveragehttps://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/
62The Register (Sep 29) - Custom malware used in Citrix 0-day attacks targeting govt, banks, professional servicesPress and vendor coveragehttps://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867
63Unit 42 (Palo Alto Networks) - NetScaler zero-days threat brief (Sep 27, updated Sep 28)Press and vendor coveragehttps://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/
64Cybersecurity Dive (Sep 28) - Shadowserver: more than 20,000 instances exposedPress and vendor coveragehttps://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/
65Help Net Security (Sep 29) - NetScaler zero-day exploitation escalates into mass attacks (Lupovis, Censys)Press and vendor coveragehttps://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/
66Ingeniøren (Sep 30) - Alvorlige huller i kendt software: PET, Forsvaret og Politiet hastelukker systemerPress and vendor coveragehttps://ing.dk/artikel/alvorlige-huller-i-kendt-software-pet-forsvaret-og-politiet-hastelukker-systemer
67SDxCentral (Sep 29) - NetScaler bugs bring critical sectors down in Europe (citing Techzine)Press and vendor coveragehttps://www.sdxcentral.com/news/netscaler-bugs-bring-critical-sectors-down-in-europe/
68Cybersecurity Dive (Sep 29) - Citrix NetScaler exploitation began days before public notificationPress and vendor coveragehttps://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/
69heise online (Sep 27) - New zero-day exploits in Citrix NetScalerPress and vendor coveragehttps://www.heise.de/en/news/Security-researchers-warn-New-zero-day-exploits-in-Citrix-Netscaler-11467269.html
70Dark Reading (Sep 29) - Dual NetScaler Zero-Days Trigger Chaos for Citrix CustomersPress and vendor coveragehttps://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix
71Omroep Brabant (Sep 27) - Storing bij ziekenhuizen door kritieke kwetsbaarheden in systeem (Amphia, ETZ, Z-CERT)Press and vendor coveragehttps://www.omroepbrabant.nl/nieuws/6028828/storing-bij-ziekenhuizen-door-kritieke-kwetsbaarheden-in-systeem
72Maurice_Sec on X - notes from the field on NetScaler Console IoC scanner findingsCommunityhttps://x.com/Maurice_Sec/status/2104541998858240487
73r/Citrix - "Netscaler leak?" thread (~Sep 26)Communityhttps://www.reddit.com/r/Citrix/comments/1wqjk9a/netscaler_leak/