Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
Summary
Multiple security firms have observed active exploitation of two NetScaler vulnerabilities, identified as CVE-2026-88771 and CVE-2026-88772. These zero-day attacks have been targeting organizations within the government and finance sectors for several weeks.
IFF Assessment
The exploitation of zero-day vulnerabilities in critical infrastructure like NetScaler represents a direct threat to organizations, making it bad news for defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 30, 2026. Known ransomware use: Unknown.
Defender Context
Organizations using NetScaler devices should prioritize patching these vulnerabilities immediately, as active exploitation means they are already at risk. Defenders need to be vigilant for indicators of compromise related to these CVEs and ensure their network security devices are up-to-date.