[ZERO-DAY] Your VPN Login Page Was Exploited for Weeks Before Anyone Got a Patch: Citrix NetScaler CVE-2026-88772
$ ./edge_exposure_audit.sh --product=netscaler --window=2026-09-24..10-01
> Pulling Citrix bulletin CTX697096 [published 09-27]...
> Pulling CISA KEV + NVD record for CVE-2026-88772...
> Pulling Mandiant/GTIG, Unit 42, GreyNoise reporting...
[KEV_LISTED] [FORENSIC_TRIAGE_REQUIRED]
Citrix patched two NetScaler Gateway zero-days on Sept 27, but researchers say attacks began in early September and patching won't remove anyone already inside. If your remote-access login runs on NetScaler, ask your MSP for the build number, the web-shell hunt results, and which passwords went through it.
ACCESS_FILE