# Google researchers trace NetScaler attacks to early September

_Published Wednesday, September 30, 2026 at 3:21 PM EDT · Security · Latest · Tier 2 — Notable_

![Google researchers trace NetScaler attacks to early September — Primary](https://img.helpnetsecurity.com/wp-content/uploads/2026/09/29153608/netscaler-1-1500.webp)

Mandiant and Google Threat Intelligence Group have identified dozens of organizations affected by exploitation of NetScaler flaw CVE-2026-88772 across North America and Europe, Help Net Security reported. Their findings trace attacks to at least early September and describe intrusions into government, financial services, education, telecommunications and professional services organizations.

The flaw affects appliances with DTLS enabled and lets attackers bypass authentication to gain root-level access. Researchers found web shells used for persistence and a tunneling tool that proxies traffic into internal networks. Mandiant CTO Charles Carmakal warned that installing a fixed version does not remove existing attackers or address stolen credentials.

## Sources

- [Help Net Security](https://www.helpnetsecurity.com/2026/09/30/cve-2026-88772-netscaler-exploitation-zero-day/)

---
Canonical: https://techandbusiness.org/newswire/aQI7BXCtteP2WcxTVqiy7A
Published: 2026-09-30T19:21:42.116Z
Story chronology: 2026-09-30T12:33:38.000Z
Retrieved: 2026-09-30T21:24:17.501Z
Publisher: Tech & Business (techandbusiness.org)
