Assume compromise: Hackers are mass-exploiting Citrix NetScaler systems in ongoing cyberattacks
Governments, companies, and organizations are scrambling to patch their Citrix NetScaler systems, amid warnings of an ongoing mass-hacking campaign that dates back to at least early September.
To recap: News first publicly emerged on a Reddit thread last week that there were rumblings of NetScaler systems getting compromised. Citrix hadn't said anything publicly yet, but rather than leave things to chance, some were advised to pull their systems from service fearing a potential mass-hacking incident unbeknownst to the tech maker.
Citrix's NetScaler systems are used by organizations to ensure that only authorized employees are allowed onto its network and can use certain applications. By acting as a digital gatekeeper aimed at keeping unauthorized users out, this also makes it a target for hackers, as a successful compromise of the system means they can defeat its protections and walk right into the organization's network.
Citrix has since confirmed the existence of several vulnerabilities, including two that are under active exploitation: CVE-2026-88771 and CVE-2026-88772 both allow hackers to run malicious code on an affected NetScaler system from over the internet.
Google-owned incident response firm Mandiant said it's now identified dozens of organizations across North America and Europe that have been hacked since early September, according to the firm's chief technology officer Charles Carmakal in a post on LinkedIn. Cyberscoop reports that Mandiant's timeline of known exploitation might shift even further back as new incidents are uncovered.
Carmakal added that a range of sectors are affected, including government, financial services, education, telecoms and legal and professional services. Cybersecurity Dive reports that some Dutch hospitals pulled their NetScaler systems from service, causing outages to patient portals.
There are at least 21,000 internet-facing NetScaler devices online as of October 1, according to public data from the ShadowSever Foundation.
Given that there was at least a three-week gap between the earliest known exploitation and Citrix releasing fixes, you may want to assume compromise of any unpatched NetScaler system on your network. U.S. cybersecurity agency CISA is urging organizations to patch their systems after receiving reports from hacked victims and threat intelligence companies "confirming that threat actors are actively exploiting these vulnerabilities globally." CISA took a step further than usual by asking organizations that suspect compromise to "preserve forensic evidence" prior to applying updates, as patches may result in a loss of visibility into the attack.
As always, the cyber threat folks at IFIN have a solid thread for incident responders with a timeline of events, resources, and additional context for threat hunters.
It's not yet known who is behind the attacks. Mandiant said that this latest mass-hacking campaign is part of an ongoing trend of hackers "continued targeting of edge devices to gain initial access to victim networks," in part because many enterprise tech companies produce security products, including firewalls and VPNs, with buggy and insecure software. Google's own threat data shows that edge devices made up about half of all zero-day attacks in the enterprise, but that the number is likely an undercount.
Citrix isn't alone in this; several other makers of edge devices and other security tech vendors have a history of having to respond to zero-day attacks. It's worth reflecting back on this Bloomberg ($) story about how private equity companies, including Citrix's chief executive, prioritized chipping away at the company's top talent and engineers through multiple rounds of layoffs at a time when Citrix vulnerabilities were ranked top of CISA's most exploited list.
~this week in security~ is my weekly cybersecurity newsletter and blog supported by readers like you. Please consider signing up for a paid subscription starting at $10/month for access to exclusive articles, analysis, and more.
Or, you can submit a one-time tip or gift a paid subscription to show your support!
Recent stories include: How a phone call allowed a hacker to steal millions of people's personal data | A breach of over 150 million U.S. and Canadian driver's license photos is an anonymity disaster | Apple opens the door to a nightmare world of always-listening tech | How residential proxy networks are hiding hackers in your home | When AI chatbots and LLMs get legal, check your privilege | Vigilantism comes for Flock