Skip to content
Critical Citrix NetScaler Zero-Days Exploited Amid $387M Crypto Hack

Critical Citrix NetScaler Zero-Days Exploited Amid $387M Crypto Hack

First seen 28 Sep 2026, 17:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 18:20 UTC
  • •Two critical zero-day vulnerabilities in Citrix NetScaler are actively exploited.
  • •CISA has issued a patch deadline of September 30, 2026, for affected systems.
  • •Bitget suffered a $387 million breach attributed to North Korean hackers.

Citrix has confirmed that two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in its NetScaler ADC and Gateway products are being actively exploited. These vulnerabilities allow unauthenticated attackers to execute arbitrary commands and potentially disrupt services. CISA has added these flaws to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to apply patches by September 30, 2026. The vulnerabilities were disclosed on September 27, 2026, and are rated critical with a severity score of 9.5/10. In a separate incident, cryptocurrency exchange Bitget resumed withdrawals after a breach attributed to North Korean hackers resulted in the theft of over $387 million. The attack involved unauthorized transfers from hot wallets, while cold wallets remained secure. The situation highlights ongoing threats from both state-sponsored actors and opportunistic cybercriminals targeting critical infrastructure and financial systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-02-06
CVE-2024-0244 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-11
CVE-2026-42608 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-27
CVE-2026-63077 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-07
CVE-2026-86296 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-86510 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-09
CVE-2026-85102 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-14
CVE-2026-90898 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-15
CVE-2026-77179 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-16
CVE-2026-89775 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-18
CVE-2026-93485 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (6)

Following this threat?

Track Clop, Kimsuky and PamStealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed