Zero-day exploitation attempts reportedly targeted Citrix NetScaler Gateway before disclosure
GreyNoise says it observed attempts to exploit a Citrix NetScaler Gateway zero-day on September 24. The vulnerability is now tracked as CVE-2026-88771.
TLDR
GreyNoise says its existing detections flagged the source IP as malicious within seconds of the September 24 attempts, three days before the vulnerability was publicly disclosed. The zero-day is now tracked as CVE-2026-88771.
Combined views
14.7K
2 Sources, first seen 4h ago
125 likes
