Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Summary

Multiple security firms have observed active exploitation of two NetScaler vulnerabilities, identified as CVE-2026-88771 and CVE-2026-88772. These zero-day attacks have been targeting organizations within the government and finance sectors for several weeks.

IFF Assessment

FOE

The exploitation of zero-day vulnerabilities in critical infrastructure like NetScaler represents a direct threat to organizations, making it bad news for defenders.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 30, 2026. Known ransomware use: Unknown.

Defender Context

Organizations using NetScaler devices should prioritize patching these vulnerabilities immediately, as active exploitation means they are already at risk. Defenders need to be vigilant for indicators of compromise related to these CVEs and ensure their network security devices are up-to-date.

Read Full Story →