Cyberreport
Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
The brief
Mandiant and Google Threat Intelligence report active exploitation of CVE-2026-88772 in Citrix NetScaler ADC and Gateway appliances. Their investigation describes unauthorized initial access followed by web shells and tunneling tools used for persistence, reconnaissance and credential theft. The report links Citrix’s updates and provides containment guidance, noting evidence of likely affected organizations across several sectors in North America and Europe.
AI-assisted brief
Source Google Threat Intelligence
Read full article

