LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
CVE-2026-88771critical

Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services

Attackers have exploited two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to compromise government agencies, financial services firms, educational institutions, and legal and professional services organizations across North America and Europe. The exploitation campaign began in early September, weeks…

ZeroDay News ·

Source: The Register — Security

Attackers have exploited two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to compromise government agencies, financial services firms, educational institutions, and legal and professional services organizations across North America and Europe. The exploitation campaign began in early September, weeks before Citrix publicly disclosed the vulnerabilities.

CVE-2026-88771 is a remote code execution flaw that allows an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service, particularly when DTLS is enabled, which is the default setting for VPN virtual servers. Both vulnerabilities received critical CVSS scores of 9.5.

Security researchers observed attempts to exploit CVE-2026-88771 against a Citrix NetScaler Gateway as early as September 24. The broader campaign leveraging CVE-2026-88772 has been active since at least early September. Citrix confirmed that exploitation of both CVEs on unmitigated NetScaler deployments has been observed.

The vulnerabilities were initially discovered during incident response and forensic investigations at organizations that had already been compromised, indicating that both the exploitation and Citrix's awareness of the issues predated public disclosure. This has raised concerns among security experts regarding the vendor's timeline for disclosing critical vulnerabilities, especially those under active attack.

Attackers in this campaign have deployed custom malware to establish persistent root access and proxy traffic into internal corporate networks. This post-exploit toolkit includes WHIPSHOT, a PHP web shell, and SLAPSHOT, a TCP tunneling tool written in Python.

WHIPSHOT is designed to appear as a Debian package and conceals Base64-encoded command-and-control payloads within native HTTP headers. It functions as an HTTP transport bridge for SLAPSHOT. SLAPSHOT, in turn, accepts commands from WHIPSHOT and forwards arbitrary TCP streams to internal hosts.

The supported commands for SLAPSHOT include `open` to establish an outbound TCP socket, `push` to write data to an open session, `pull` to read data from an open session socket, `exch` for sending and receiving command-and-control data, `close` to terminate a network session, and `ping` for basic health checks. In at least one observed intrusion, the threat actor utilized this proxy to conduct internal reconnaissance and steal credentials.

While no specific attribution has been made public, historically, NetScaler vulnerabilities have been exploited by both state-sponsored groups and ransomware operators. The continued targeting of edge devices like application delivery controllers, VPN gateways, and firewalls is a persistent trend, as these devices offer direct access from the internet to corporate networks, often bypassing endpoint detection and other security layers.

Organizations using Citrix NetScaler ADC and NetScaler Gateway appliances are strongly advised to apply the security updates immediately. However, security experts also recommend thoroughly examining systems for signs of compromise *before* patching. If evidence of web shells or other malicious files is found, it is crucial to preserve evidence and investigate the scope of the compromise, as patching alone may not remove the threat actor from the environment.

vulnerabilities in this storyCVE-2026-88771CVE-2026-88772
citrixnetscalervulnerabilitymalwarezero-day
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.