Read three outlets on the Citrix NetScaler attacks and you get at least four start dates. The earliest, Aug. 21, comes more than five weeks before the Sept. 27 advisory that most defenders used to start their clocks. The gap between those dates is the finding, and it changes where a compromise assessment has to begin.
What the three accounts say
Citrix disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway on a Sunday, two of them confirmed as exploited, according to the UK’s National Cyber Security Centre. The two are CVE-2026-88771, which allows an unauthenticated remote attacker to execute arbitrary commands, and CVE-2026-88772, a memory buffer flaw that leads to remote code execution or denial of service. Three outlets then covered what followed, and each told a different part of it.
CyberScoop: the gap before anyone knew
CyberScoop built its report around detection time. It reported that Mandiant dates the earliest known exploitation of CVE-2026-88772 to Sept. 3, and that attacks were not confirmed until late the week before the advisory. It added that GreyNoise has seen CVE-2026-88771 exploited since at least Sept. 24, with the campaign likely starting earlier. Mandiant’s Charles Carmakal counted “dozens” of affected organizations, per the same article, and Mandiant told CyberScoop its timeline could still move as responders find more evidence.
Cybersecurity Dive: the disruption
Cybersecurity Dive led with fallout. Dutch hospitals Frisius MC and Amphia suspended online access to patient portals after taking NetScaler-based systems offline, and the Dutch NCSC alerted critical infrastructure providers on the Friday before the advisory. Its timeline reached back further than CyberScoop’s: Palo Alto Networks told the outlet it traced activity to Aug. 21. Arctic Wolf counted at least 78 targeted organizations, and the Shadowserver Foundation counted more than 20,000 NetScaler instances exposed and potentially vulnerable.
The Hacker News: a third flaw arrives
The Hacker News covered the part the other two could not, because it happened later. On Oct. 5 it reported a patch for CVE-2026-88779, a memory overflow with a CVSS score of 8.7 that can cause denial of service when NetScaler is configured as a SAML service provider or identity provider. Citrix said it had observed targeted attacks on unmitigated deployments and had not identified an impact on the integrity of customer data. The outlet reported that CISA added the flaw to its Known Exploited Vulnerabilities catalog with an Oct. 7 federal deadline.
Where the accounts differ
The start dates differ, and they are not all measuring the same thing. Palo Alto’s Aug. 21 is threat activity. Mandiant’s Sept. 3 is the earliest known exploitation of one specific CVE. GreyNoise’s Sept. 24 is the earliest sighting for the other. Each is a floor set by what that vendor’s telemetry could see, and none of them is a confirmed first day.
The framing differs too. Cybersecurity Dive describes what may be targeted espionage against government agencies and critical infrastructure providers. CyberScoop quotes Carmakal expecting “broad and opportunistic exploitation” of both zero-days by a variety of threat actors in the near term. Those two readings call for different postures: the first says check whether you were selected, the second says assume you will be scanned.
On the basics the three agree. All describe edge appliances compromised before a fix existed, and all report that the fixes arrived after intrusions had started.
The sequence of warnings also differs by outlet. Cybersecurity Dive reports that the Dutch NCSC alerted providers on the Friday, CyberScoop reports first unconfirmed rumors of the attacks nearly two days before Citrix disclosed, and the advisory followed on Sunday. Defenders in different countries therefore got their first signal on different days, and the date a team treats as day zero often depends on which of those signals reached it.
What the coverage adds up to
No single article says what the three say together: the advisory date is the worst place to start a hunt. A team that began its review on Sept. 27 would have looked at the days after the first confirmed exploitation and missed at least five weeks before it.
The reason sits in the appliance class. CyberScoop quotes Mandiant on why attackers favor these devices: “Because most edge devices do not support endpoint detection and response (EDR) monitoring, targeting them, particularly through exploiting zero-day vulnerabilities, provides threat actors with an infection vector that is difficult to detect and prevent, and the opportunity to scale a campaign as long as the exploit remains undiscovered.” CyberScoop adds that edge devices accounted for 48% of enterprise zero-days last year, per Google Threat Intelligence Group. With no endpoint agent on the box, logs from before the advisory often do not exist, so the only evidence of an early intrusion may be what the attacker left behind.
That is why the dates in the reports are minimums. Each vendor is reporting the earliest thing it can prove, and the proof depends on who had sensors in front of which customers. Our read is that a lookback anchored to the earliest published date, with extra margin, is the defensible choice until responders stop revising their timelines.
Why the exposure is not evenly spread
The sectors named in the coverage depend on this appliance in different ways. Errol Weiss, chief security officer at Health-ISAC, told Cybersecurity Dive: “In healthcare IT and OT environments, NetScaler often sits at the edge of the network, providing secure remote access and application delivery.” Dutch hospitals Frisius MC and Amphia suspended patient portal access while they took NetScaler-based systems offline, which shows what isolating one of these appliances can cost. Our read is that the sectors Mandiant listed (government, financial services, education, telecom, legal and professional services) should check their own log retention against the Aug. 21 date instead of assuming it matches a peer’s.
What it means for the security leader
Patching closes the door and does not clear the house. Carmakal said so directly in a LinkedIn post on Tuesday, according to Cybersecurity Dive: “Upgrading alone will not eradicate post-exploitation access or address stolen credentials.”
The NCSC advice reads the same way. It tells defenders to isolate affected systems and replace them with new, fully up-to-date systems where possible, investigate for compromise using the published indicators of compromise, and only then re-introduce the appliance. We made the case for that sequence in Replace an Exploited Edge Appliance Before You Trust It Again. The window question is the same one we raised in Attackers Probed Mail Servers Between a Zimbra Fix and Disclosure: attackers were on those servers before the fix and the advisory.
Three checks are worth finishing this week:
- Inventory NetScaler appliances running 14.1 before 14.1-73.37 or 13.1 before 13.1-64.23, the affected ranges the NCSC lists.
- Find the earliest date for which you hold authentication, VPN and web server logs from those appliances, and note whether they reach back to Aug. 21.
- Identify any appliance configured as a SAML service provider or identity provider. CVE-2026-88779 applies to those, and Citrix’s fix is 14.1-73.41 or 13.1-64.28 and later releases.
The defender close
Treat Aug. 21 as the working start date until a vendor publishes an earlier one. Pull every log you hold for NetScaler from that date forward, and check the downstream Citrix infrastructure Cybersecurity Dive lists: StoreFront servers, Delivery Controllers, and Windows Event Logs for unusual logins or unexpected Remote Desktop Protocol use. Rotate credentials that passed through the appliance and revoke active sessions, steps Cybersecurity Dive lists among the recommendations for suspected compromises. If your retention window is shorter than five weeks, write that down as a risk, because it caps how sure you can be.
Source: NCSC alert on exploitation of Citrix NetScaler ADC and Gateway vulnerabilities

