Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 exploited for weeks by attackers.
Summary
Multiple security firms, including Mandiant and GreyNoise, have confirmed active exploitation of NetScaler ADC and Gateway vulnerabilities CVE-2026-88771 and CVE-2026-88772. Attackers are using these flaws to gain root access, deploy web shells like WHIPSHOT and SLAPSHOT, and move laterally within victim networks. Exploitation has been ongoing since early September, impacting organizations across government, finance, and other sectors, with suspected involvement of state-sponsored actors.
Full text
Google’s Mandiant and Threat Intelligence Group (GTIG) have published details on attacks exploiting the NetScaler zero-days that Citrix patched over the weekend. The vulnerabilities are tracked as CVE-2026-88771 and CVE-2026-88772, and they affect NetScaler ADC and NetScaler Gateway instances. Attackers can exploit these critical flaws for unauthenticated remote code execution. Before Citrix released patches, government cybersecurity agencies and security firms took the rare step of urging administrators to disconnect affected NetScaler appliances from the internet immediately while zero-day exploitation investigations were ongoing. Mandiant and GTIG, whose report focuses on the exploitation of CVE-2026-88772, spotted attacks in late September. However, their investigation found that the zero-day campaign has been “ongoing since at least early September.” The attacks likely impacted organizations in North America and Europe. These organizations are in the government, financial services, education, legal, and professional services sectors. The attackers exploited the vulnerability to gain root access to NetScaler ADC and Gateway appliances. They then changed the appliance’s web server configuration so they could plant web shells and run them with root privileges.Advertisement. Scroll to continue reading. Mandiant found previously unseen malware in the attacks, including a PHP web shell named WHIPSHOT and a Python-based tunneling tool named SLAPSHOT. The two work together to give the attackers a path from the compromised appliance into the victim’s internal network. According to Mandiant, the tools enable internal reconnaissance, lateral movement and credential theft. In at least one intrusion, the hackers used the tunnel to manually explore the internal network and steal credentials. Mandiant also saw signs that the threat actor may be managing similar web shells in multiple compromised environments. Mandiant CTO Charles Carmakal noted that dozens of organizations have been hit, including by suspected state-sponsored threat actors. “We expect broad and opportunistic exploitation of CVE-2026-88772 and CVE-2026-88771 by a variety of threat actors in the near term,” Carmakal warned. Cybersecurity expert Kevin Beaumont reported being aware of more than 100 victim organizations as of Tuesday, noting that the attacks appear to be part of an espionage campaign. Security firm WatchTowr, one of the first to confirm in-the-wild exploitation, has released technical details on both CVE-2026-88772 and CVE-2026-88771. Threat intelligence company GreyNoise observed zero-day exploitation attempts on September 24, several days before the flaws were disclosed and patched. “The [malicious cyber actor] attempted to set both the Set User ID (setuid) and Set Group ID (setgid) bits on /bin/sh to obtain a root shell and install a password-protected webshell that accepts communication by the cookie value sent by the adversary. This may be to avoid persisting their commands in web logs,” GreyNoise explained. Palo Alto Networks reported that there had been roughly 50,000 potentially exposed NetScaler instances as of September 27. Related: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks Related: Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ Related: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data LeaksPentagon Personnel Agency Data Breach Impacts 3 Million PeopleOpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier TrainingApple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ Nvidia Unveils AI Agent Safety Platform With Hardware-Based WatchdogCitrix Confirms 2 NetScaler Zero-Days After Admins Pulled the PlugMicrosoft SharePoint Flaw CVE-2026-65660 Now Exploited in AttacksNorth Korea Suspected in $351 Million Bitget Crypto Heist Latest News WatchGuard Patches Critical Fireware OS Code Injection VulnerabilityChrome, Firefox Updates Patch Over 100 VulnerabilitiesAnthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking LawsuitRussian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent AttacksShinyHunters Defiant After FBI Calls on Members to Come ForwardHigh-Severity Vulnerabilities Patched in OpenSSL, WolfSSLTrump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI DevelopmentOpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the Move David Cass has joined Grayscale Investments as Chief Risk Officer. He joins the crypto investment funds firm from Keyrock, where he served as Chief Information Security Officer. Thomas Dager has been appointed Vice President and Chief Information Security Officer at The Goodyear Tire & Rubber Company.Alex Stamos has become Chief Information Security Officer at Cognition.More People On The MoveExpert Insights Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-88771
- cve — CVE-2026-88772
- malware — WHIPSHOT
- malware — SLAPSHOT