Weekly Intelligence Summary: NetScaler Zero-Day Vulnerabilities

This week’s Orpheus Intelligence Summary focuses on the active exploitation of two critical zero-day vulnerabilities affecting NetScaler ADC and NetScaler Gateway: CVE-2026-88771 and CVE-2026-88772. Both vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities catalogue following confirmed exploitation in the wild.

Successful exploitation can provide threat actors with significant access to affected appliances, including root-level access in observed CVE-2026-88772 attacks. Post-compromise activity has included web shell deployment, persistence, access to internal networks and credential theft. Because NetScaler appliances commonly provide VPN, application delivery and authentication services at the network edge, compromise can create a route into wider enterprise environments.

This week’s summary also covers active exploitation affecting Cisco Catalyst SD-WAN Manager, Microsoft SharePoint and FortiMail, alongside ShinyHunters activity targeting Oracle PeopleSoft, JadePuffer Azure campaigns and Russia-affiliated Callisto phishing operations.

Download the full Weekly Intelligence Summary

Orpheus Weekly Intelligence Summary on critical NetScaler zero-day vulnerabilities, 5 October 2026
Scroll to Top

Become a Partner

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Please complete the form below and we’ll be in touch shortly.