# Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances

Publisher-attributed story with a reviewed brief or permitted publisher paragraph. The original publisher is responsible for the linked reporting.

- Publisher: Google Threat Intelligence
- Author credit: Mandiant; Google Threat Intelligence Group
- Category: Cyber
- Original publication time: 2026-09-29T14:00:00Z
- First observed by NexusTechWire: 2026-10-01T20:28:45Z
- Original source: https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances/
- NexusTechWire record: https://nexustechwire.com/news/news-8ae589a85d811f9a6a42

## The brief

Mandiant and Google Threat Intelligence report active exploitation of CVE-2026-88772 in Citrix NetScaler ADC and Gateway appliances. Their investigation describes unauthorized initial access followed by web shells and tunneling tools used for persistence, reconnaissance and credential theft. The report links Citrix’s updates and provides containment guidance, noting evidence of likely affected organizations across several sectors in North America and Europe.

AI-assisted NexusTechWire summary, checked against the linked source on 2026-10-01T20:26:11.940Z. Not independent reporting.

Read the full original: [Google Threat Intelligence](https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances/)

This record does not reproduce the complete article or represent independent confirmation of every source claim.
