INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

NetScaler Zero-Day Attacks Target Government and Finance Orgs Worldwide

| 2026-09-28 07:13 CRITICAL MEDIUM EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Government, finance organizations were targeted in a weeks-long series of NetScaler zero-day attacks that began at least early September and continued through late September. The attackers are believed to be suspected state-sponsored threat actors, although no specific attribution has been confirmed by the sources. At least 100 victim organizations have been affected across North America and Europe, with those impacted including government agencies, financial services firms, educational institutions, legal practices, and professional services companies. Attackers exploited critical vulnerabilities in NetScaler ADC and Gateway instances to gain root access, plant web shells, and steal credentials using tools that enable internal reconnaissance, lateral movement, and credential theft; these exploits were likely carried out by a variety of threat actors in the near term.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-88772, CVE-2019-18935 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

e6•••••.sig
e6•••••.ico
ef3064••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
944062••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
ee3bd4••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
10f705••••••••••••••••••••••••••
18fb4e••••••••••••••••••••••••••
1dbfda••••••••••••••••••••••••••
0a4be0••••••••••••••••••••••••••
972f86••••••••••••••••••••••••••••••••••
fe619d••••••••••••••••••••••••••••••••••
e23046••••••••••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
w3•••••.exe
45.138.•••.•••
206.82.•••.•••
65.98.•••.•••
2.59.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-88772CVE-2026-88772 CVE-2019-18935CVE-2019-18935 CVE-2026-88771CVE-2026-88771
Target & Sectors
BENELUX BENELUX DACH DACH EUROPE EUROPE NORTH_AMERICA NORTH_AMERICA educationeducation financefinance governmentgovernment legallegal technologytechnology
Incident Timeline
‎September 2026
Attackers worldwide exploited a NetScaler zero-day vulnerability to gain root access, targeting multiple sectors including government, financial services, technology, education, and legal and professional services.
industry Government
industry Education
industry Legal
industry Technology
attribution Mandiant Consulting
attribution Google Threat Intelligence Group
‎September 24
Threat actors worldwide exploited a previously unknown vulnerability in NetScaler on September 24, several days before the flaw was publicly disclosed and patched.
‎September 27
Attackers worldwide exploited a zero-day vulnerability in NetScaler instances, exposing approximately 50,000 systems as of September 27.
general_metric 50,000 exposed NetScaler instances
‎September 28, 2026
Attackers worldwide exploited the CVE-2026-88771 vulnerability in NetScaler ADC and Gateway to gain root access, with GreyNoise detecting increased malicious activity starting around 8:30 a.m. EDT on September 28, 2026.
vulnerability CVE-2026-88771
organisation GreyNoise
organisation NetScaler ADC
organisation Censys
infrastructure 42,735 hosts
general_metric 323,527 web properties
‎2026/09/28
Threat actors exploited CVE-2026-88772 and CVE-2026-88771 vulnerabilities in unpatched Citrix NetScaler ADC and Gateway appliances to gain root access, deploy web shells, and conduct internal reconnaissance.
infrastructure 13,549 hosts
organisation SweetPotato
organisation ASEC
infrastructure Windows
organisation WordPress
organisation Telegram
organisation Google
organisation TCP
organisation WHIPSHOT
victims 100 victim organizations
organisation CVE-2026
organisation NetScaler ADC
organisation NetScaler Gateway
organisation WatchTowr
organisation Mandiant Consulting
organisation the NetScaler Packet Processing Engine
organisation NSPPE
organisation the Datagram Transport Layer Security
organisation DTLS
organisation Citrix NetScaler ADC
organisation NetScaler
organisation PHP
organisation the Set User ID
organisation Set Group ID
organisation GreyNoise
infrastructure Linux
organisation Root Access
organisation GET
organisation Application Delivery Controllers
organisation EDR
organisation Microsoft
organisation Amazon
organisation NetScaler VPX
‎2026/09/29
Attackers worldwide exploited a NetScaler zero-day vulnerability for root access, escalating from mass reconnaissance to full-scale exploitation across multiple independent actors and campaigns.
tactic Reconnaissance
organisation The Hacker News
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
victims
100
Victim Organizations
Metrics
infrastructure
13,549
Hosts
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
42,735
Hosts