GreyNoise saw exploitation activity starting at least 24 September against a target in Japan.
Please see our latest Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778. Citrix urges affected customers to install the relevant updated versions as soon as possible. bit.ly/3T4RXGY

Sep 27, 2026 · 4:40 PM UTC

11
21
180
28,032
Sort replies: Relevant Recent Liked
Why didn’t you share it back then?
1
19
1,755
Replying to @ImposeCost
Will GreyNoise publish IOC's? That's a long time between exploitation and patch yet we still have nothing to hunt for.
4
937
Replying to @ImposeCost
Can you share the IOC?
1
2
1,248
Replying to @ImposeCost
Any payload artifacts you can share?
1
453
Replying to @ImposeCost
That was late. Look back at Sep 20
144
Replying to @ImposeCost
It says a lot when people are asking Threat Intelligence companies for IOCs rather than the creator of the software.
4
685
Replying to @ImposeCost
Are you planning to write a blog article on this eventually? Love your content but would like see the event through the Greynoise perspective. Keep up the good work 💪
1
654
Is it normal Linux post exploitation commands I would hunt for in the Citrix logs?
1
626