Citrix NetScaler zero-day exploitation is escalating from patch alerts to full post-compromise tradecraft: attackers are using CVE-2026-88772 and the separately exploited CVE-2026-88771 to plant web shells, gain root access, steal credentials and move into internal networks. The campaign, already flagged in
earlier 4sysops coverage of the NetScaler RCE flaws, now appears to have been active since at least early September across government, finance, education, legal and professional-services targets.
Source