CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Swarming Against Citrix 0-Day Exploitation

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8754

As cited

Copy frozen at (site build).

vulnerabilities

Swarming Against Citrix 0-Day Exploitation

On September 24, 2026, a threat actor at IP address 149.104.78.141 attempted to exploit a zero-day vulnerability in Citrix NetScaler Gateway before public disclosure. GreyNoise detected the malicious behavior through behavioral analysis despite the absence of CVE-specific signatures at that time.

Why it matters: Security teams running Citrix NetScaler Gateway need to know that zero-day attacks are occurring in the wild, and behavioral detection tools can identify exploitation attempts when signature-based defenses are unavailable.

VendorsCitrix
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary