Summary
- Mandiant says CVE-2026-88772 exploitation has been active since at least early September.
- Likely affected organisations span Europe and North America across government, finance, technology, education, energy, utilities, and professional services.
- The findings expand earlier Citrix warnings by establishing a longer exploitation window and broader sector exposure.
New forensic evidence has widened the scale of the current Citrix NetScaler incident, with Mandiant saying exploitation of one of the newly disclosed zero-days began in early September and likely affected organisations across several European sectors.
The findings add a clearer exploitation timeline to Citrix’s emergency patching disclosures and the service restrictions imposed by Dutch institutions after the vulnerabilities became public.
Mandiant Consulting and Google Threat Intelligence Group say they identified active exploitation of CVE-2026-88772 affecting NetScaler ADC and NetScaler Gateway appliances. Their evidence indicates organisations in Europe and North America were likely affected across government, financial services, technology, education, energy and utilities, and legal and professional services.
Citrix has also disclosed active exploitation of a second zero-day, CVE-2026-88771.
CVE-2026-88772 can bypass authentication and trigger an unhandled termination in the NetScaler Packet Processing Engine, establishing initial root-level access. That places the weakness at a particularly sensitive point in enterprise architecture because NetScaler Gateway appliances are often internet-facing systems used to broker access to internal services.
Mandiant’s timeline changes the response calculation. If exploitation began weeks before the vulnerability was publicly disclosed, organisations that patched promptly after receiving the advisory may still have been compromised while the flaw remained a zero-day.
Installing the fixed software closes the vulnerable path, but it does not remove persistence, credentials, or secondary access established before the upgrade.
That makes forensic scoping central to the response. Organisations that operated vulnerable appliances during September need to establish whether exploitation occurred before patching rather than treating the presence of the latest version as proof the incident is closed.
The cross-sector victim profile also shows how shared infrastructure creates common exposure across otherwise very different organisations. Government departments, banks, universities, energy operators, technology companies, and legal practices can all depend on the same remote-access platform.
Security appliances and gateways are attractive targets precisely because they sit at trusted network boundaries. Successful exploitation can place an attacker beyond controls designed to protect ordinary endpoints, while the appliances themselves may not carry the same endpoint detection tooling as conventional servers.
Forensic work can also be harder. Logs may be limited, emergency upgrades can alter evidence, and incident responders may need to preserve appliance state while an organisation is simultaneously trying to restore secure remote access.
The European exposure creates further reporting questions for organisations subject to sector regulation, NIS2 obligations, data-protection rules, or operational-resilience requirements. Whether notification is required depends on the organisation and actual impact, but a multi-week exploitation window increases the number of operators that need to investigate rather than simply patch.
Mandiant’s findings therefore move the NetScaler incident beyond vulnerability management. The unresolved question for organisations that ran affected appliances in September is not merely whether an update has been installed, but whether the gateway was reached before defenders knew what to look for.





