Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
CISA's Citrix NetScaler Patch Deadline Passes Today as Mass Exploitation Outruns Fixes, Researchers Say Backdoors Survive Patching

Since GreyNoise first logged an unsuccessful exploitation attempt against a Citrix NetScaler Gateway sensor on September 24, this campaign has moved from quiet, targeted intrusions to indiscriminate, worldwide scanning within days of the vendor's public disclosure.
Citrix published security bulletin CTX697096 on September 27, disclosing eight vulnerabilities in NetScaler ADC and NetScaler Gateway, its widely deployed load-balancing and VPN appliances. Two were already being exploited as zero-days: CVE-2026-88771, a pre-authentication remote code execution flaw from improper input validation (CVSS 9.5), and CVE-2026-88772, a memory overflow in the DTLS protocol implementation that also leads to RCE (CVSS 9.5). Citrix said in its advisory that "exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed."
The Cybersecurity and Infrastructure Security Agency added both CVEs to its Known Exploited Vulnerabilities catalog on September 27 and, under Binding Operational Directive 26-04, ordered all Federal Civilian Executive Branch agencies to secure every vulnerable appliance by today, September 30, according to Tech Times. That directive only legally binds federal agencies. Private companies running the same exposed appliances have no such mandate, even as Palo Alto Networks told CyberScoop it had identified more than 50,000 publicly exposed NetScaler instances as of September 27, and Shadowserver Foundation separately put exposed, at-risk instances above 20,000, according to Cybersecurity Dive. Neither figure has been reconciled, and it's unclear whether the gap reflects different scanning methodologies or different points in time.
A Weekend of Unofficial Warnings
Public alarm outran Citrix's own disclosure. Dark Reading reported that customers first flagged possible exploitation in a Reddit thread on September 25, two days before Citrix's bulletin. Cybersecurity Dive reported that over that same weekend, security teams received urgent phone calls from IT security firms and government contacts telling them to disconnect servers immediately, before any official confirmation existed.
Benjamin Harris, founder and CEO of watchTowr, told CyberScoop that "the information vacuum was most striking," adding that "customers were left without communication, guidance, or even acknowledgement that the vulnerability that was rumored to exist was real." Harris said Citrix "could have warned customers that active exploitation was occurring and provided immediate defensive guidance without disclosing technical details that would help attackers." Citrix did not directly answer CyberScoop's questions about the delay, instead issuing a statement saying it had "immediately" developed and released a fix once it identified the vulnerabilities.
Then a Public Exploit Dropped
The situation shifted again on September 29, when watchTowr Labs published a proof-of-concept exploit for CVE-2026-88771. Xavier Bellekens, CEO of deception firm Lupovis, told Help Net Security that his sensor network began recording live exploitation attempts within minutes of the PoC going public. "If you run NetScaler and you haven't patched, assume you are already being probed," he said. Tech Times reported that as of its September 30 publication, fewer than one in ten vulnerable hosts had been patched.
Google's Mandiant Consulting and Google Threat Intelligence Group reported separately that they had identified active exploitation of CVE-2026-88772 dating back to at least early September, hitting government, financial services, technology, education, and legal-sector organizations across North America and Europe. Mandiant said attackers used the flaw to bypass authentication and crash NetScaler's Packet Processing Engine, gaining root access, then deployed a custom PHP web shell it named WHIPSHOT, which hides command-and-control traffic inside native HTTP headers, alongside a companion Python tunneling tool called SLAPSHOT used for internal reconnaissance and credential theft.
The Patch Doesn't Undo the Damage
Applying Citrix's patch stops new intrusions but does not remove web shells already planted during weeks of silent access. Help Net Security reported that attackers are using log-poisoning techniques, sending malicious requests to the endpoint POST /nf/auth/doAuthentication.do and exfiltrating data to a server hosted at Hetzner, IP address 138.199.200.90. Citrix has released a detection script for customers, but acknowledged, per Help Net Security, that it may fail to catch actual compromises because attackers frequently change tactics and infrastructure.
One specific number deserves scrutiny. Tech Times reported that "more than 100 organizations" were confirmed compromised before a patch existed. That figure does not appear in CyberScoop's, Cybersecurity Dive's, or Mandiant's reporting. CyberScoop instead quoted Citrix declining to disclose a compromise count, and noted researchers were still assessing the fallout as of its report. Adam Marre, CISO at Arctic Wolf, told Cybersecurity Dive that NetScaler flaws are "exactly the kind of vulnerabilities that keep government security leaders up at night because they target the systems agencies depend on to connect users, provide services and secure access."
Citrix has not published an official tally of compromised customers. Until it does, or until Mandiant and independent researchers complete their own accounting, the scope of this breach beyond exposure counts and scan data remains an open question for the organizations still deciding whether patching alone is enough.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.