CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 9323

As cited

Copy frozen at (site build).

vulnerabilities

Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited

A 16-year-old researcher disclosed a flaw in Microsoft's Titan analytics service that exposed access to 17 trillion rows of data, including employee records and Bing search analytics. Citrix patched eight critical and high-severity vulnerabilities in NetScaler, including two remote code execution zero-days (CVE-2026-88771, CVE-2026-88772) that were exploited globally for weeks.

Why it matters: Organizations using Microsoft internal services and Citrix NetScaler should assess whether they were affected by the Titan exposure or NetScaler exploitation, and apply the Citrix patches immediately to prevent active compromise.

VendorsMicrosoftCitrix
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited

A 16-year-old researcher disclosed a flaw in Microsoft's Titan analytics service that exposed access to 17 trillion rows of data, including employee records and Bing search analytics. Citrix patched eight critical and high-severity vulnerabilities in NetScaler, including two remote code execution zero-days (CVE-2026-88771, CVE-2026-88772) that were exploited globally for weeks.

Why it matters: Organizations using Microsoft internal services and Citrix NetScaler should assess whether they were affected by the Titan exposure or NetScaler exploitation, and apply the Citrix patches immediately to prevent active compromise.

VendorsMicrosoftCitrix
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary