TimelineTLP:CLEAR
Citrix NetScaler CVE-2026-88771
GreyNoise saw CVE-2026-88771 exploitation attempts on Sep 24, more than three days before public disclosure. The CVE-specific tag, deployed Sep 27, retro-tagged that activity.
7 dated events on 3 daysRetro-tagged as CVE-2026-88771 exploitation↑ ↓ to step through
13 days42
Sep 102026
07:14:57 UTC
NetScaler reserves CVE ID.
13 days with no dated recordSep 11–Sep 23
Sep 24
07:32:08 UTC
Initial reconnaissance begins.
Intention is not known. Every Sep 24 entry here comes from this one IP address.
Open in the GreyNoise Visualizer ↗
Sep 24
07:32:15 UTC
GreyNoise labeled the IP address suspicious due to methodology-based detection.
(Citrix ADC Gateway Login Panel Crawler)
Open in the GreyNoise Visualizer ↗
Sep 24
07:32:19 UTC
GreyNoise labeled the IP address malicious.
(Generic ${IFS} Use in RCE Attempt; CitrixBleed 2 CVE-2025-5777 Attempt)
Open in the GreyNoise Visualizer ↗
Sep 24
Retro-tagged as CVE-2026-88771 exploitation
07:32:19 UTC
GreyNoise observed CVE-2026-88771 exploitation attempts from this IP address.
(Citrix NetScaler CVE-2026-88771 Login Command Injection RCE Attempt) Retro-tagged after the tag's Sep 27 deployment: 3 sessions, 07:32:19 to 07:32:20 UTC.
Open in the GreyNoise Visualizer ↗
Sep 27
15:51:00 UTC
Public disclosure of CVE-2026-88771.
Sep 27
20:28:39 UTC
GreyNoise deployed the CVE-specific tag.
(Citrix NetScaler CVE-2026-88771 Login Command Injection RCE Attempt) Its retro hunt of stored sessions tagged only the Sep 24 activity.
Open in the GreyNoise Visualizer ↗
Source: CVE record; GreyNoise.
Times are UTC.
GreyNoise