Skip to content
Brief Security & Trust ·

Citrix NetScaler zero-days used in attacks; Cisco, Fortinet, Apple also hit

Help Net Security's weekly review says two NetScaler flaws were attacked before fixes existed, and mass attacks followed.

In brief
  • Citrix fixed eight serious NetScaler flaws, and two were used in zero-day attacks. Help Net Security says the attacks later grew into mass attacks.
  • The same weekly review lists zero-day attacks on Cisco SD-WAN, FortiMail and Apple's Core Graphics software.

Help Net Security said in its weekly review on 4 October that Citrix fixed eight serious flaws in NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, were used in zero-day attacks. A zero-day is a flaw that attackers use before a fix exists. Help Net Security said the attackers planted webshells, which are hidden remote-control tools, on hacked devices. The review also listed zero-day attacks on Cisco SD-WAN (CVE-2026-76504), FortiMail (CVE-2026-104286) and Apple's Core Graphics software (CVE-2026-86950). It said Cisco has now seen this kind of attack on SD-WAN five times this year.

Help Net Security reported that the NetScaler attacks grew into mass attacks and hit devices around the world for weeks. It also passed on a view from Mandiant CTO Charles Carmakal. He said suspected state-sponsored hackers were likely behind the first targeted break-ins using CVE-2026-88772, which began in early September. The review is a list of headlines. It does not say how many devices were hit, who is behind the mass attacks, or which software versions carry the fixes.

Teams that run NetScaler, Cisco SD-WAN, FortiMail or Apple systems face flaws that attackers are already using. Checking whether each vendor's fix is installed is the clear first step.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: Help Net Security.