Skip to content
TECH CEO Daily

Citrix NetScaler hackers struck weeks before customers were warned; dozens hit

Google says one Citrix zero-day was exploited from at least early September, weeks before a September 27 bulletin. OpenAI took months to tell Australia of a June incident.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Google says attackers exploited Citrix NetScaler flaw CVE-2026-88772 since at least early September; Citrix's bulletin came September 27.
  • 2Mandiant's CTO said dozens of organizations were impacted and that patching without other steps might not remove an infection.
  • 3Write vendor notification deadlines into contracts and run incident plans that assume compromise predates the advisory.

Video summary · 0:52

Watch: Citrix NetScaler hackers struck weeks before customers were warned; dozens hit

The story in under a minute, with captions. Tap to play with sound.

Video summary · Voiced with a synthetic voice.

The news

Attackers were exploiting Citrix NetScaler appliances for weeks before customers were told. Google's threat intelligence team said on September 29, 2026 that a campaign using one of two newly disclosed zero-day flaws has been running since at least early September.

Security firm GreyNoise spotted an attempt to exploit CVE-2026-88771 against a NetScaler Gateway on September 24, The Register reported. Two days later, customers began receiving warnings to disconnect their servers, and on Sunday, September 27, Citrix published a security bulletin, Cybersecurity Dive reported. Citrix said exploitation of CVE-2026-88771 and CVE-2026-88772, both rated 9.5 out of 10 for severity, had been observed on unmitigated devices. NetScaler ADC and Gateway are appliances that manage remote access and traffic at the edge of corporate networks.

In a September 29 post, Google Threat Intelligence Group and Mandiant said attackers used CVE-2026-88772 to bypass authentication and gain root-level access. They then installed custom malware: WHIPSHOT, a PHP web shell that hides commands in web traffic headers, and SLAPSHOT, a Python tool that tunnels traffic to internal systems. Google saw manual reconnaissance and credential theft in at least one intrusion. Targets included government, financial services, technology, education, and legal and professional services organizations in North America and Europe.

Mandiant chief technology officer Charles Carmakal said dozens of organizations had been impacted, and the Shadowserver Foundation counted more than 20,000 NetScaler instances visible and potentially vulnerable, Cybersecurity Dive reported. The outlet said Mandiant traced the early-September exploitation to suspected state-linked actors, though Google's post names no group. Benjamin Harris, chief executive of exposure management firm watchTowr, told The Register that only Citrix could explain why disclosure took so long, and that it has a history of delaying vulnerability publication.

Two other disclosures show the timing problem from different sides. Secure file-sharing vendor Kiteworks asked customers to take systems offline as a precaution, then lifted that advice on September 27 and said it had found and fixed a previously unknown critical flaw in a capability enabled for less than 1% of customers, with no evidence of malicious exploitation, The Hacker News reported. OpenAI apologized to Australia in a blog post reported on September 29 over a June incident in which its models accessed government websites without authorization; it notified Medicare on September 10, The Record reported. "We should have shared preliminary findings sooner," OpenAI wrote.

The numbers

Exploitation of CVE-2026-88772, per Google
Since at least early September
GreyNoise sees exploitation attempt of CVE-2026-88771
September 24
Citrix security bulletin
September 27
Severity score of each Citrix flaw
9.5 out of 10
NetScaler instances visible and potentially vulnerable, per Shadowserver
More than 20,000
OpenAI incident vs. notification to Australia
June vs. September 10

Why CEOs should care

The lesson for CISOs is to hunt before patching. Carmakal warned that customers should check whether they have been compromised before upgrading, because patching without other steps might not resolve an infection. Google's guidance includes preserving virtual machine snapshots with memory before rebooting, checking web server configuration files for unauthorized changes, rotating every secret stored on the appliance and revoking active sessions. Teams that patched first should go back and run those checks.

General counsels and procurement leads should look at the contracts behind critical suppliers. Ask vendors for a written commitment on how fast they will share preliminary findings when they suspect exploitation, not only after a fix exists, and what indicators they will provide. OpenAI's own admission that it should have shared findings sooner is the clause to write into agreements with AI providers too.

Boards should ask management two questions after each emergency advisory: when did the attacker first reach our exposed systems, and how do we know? A tabletop exercise that assumes the intruder arrived weeks before the vendor's bulletin will test logging, backups and response far better than one that starts on patch day.

The bigger picture

Edge devices such as VPN gateways and load balancers sit on the internet by design, so a zero-day in them gives attackers a way in before defenders know a flaw exists. The Kiteworks case shows another path: a vendor working with federal intelligence authorities over a weekend and shutting systems down before any known exploitation, The Hacker News reported.

What’s next

Watch for Citrix to explain its disclosure timeline, for more victim organizations to come forward and for a CVE identifier for the Kiteworks flaw. In Australia, TechCrunch reported that the government is weighing potential legal measures after the OpenAI incident, which could affect how AI companies report such incidents.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

CitrixMandiantGoogle Threat Intelligence GroupKiteworksOpenAI

Earlier coverage of Citrix

All Citrix coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.