Citrix NetScaler Zero-Days Were Exploited for Three Weeks Before the Patch, With Root Access
Root on the front door for three weeks, a shell that hides in headers, and a cleanup crew. The patch closes the door with them inside.
Suspected state-sponsored (vendor)CVE-2026-88772 DTLS heap corruptionCross-sectorEdge devices