LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
CVE-2026-88771critical

Hackers exploit Citrix NetScaler zero-day to deploy web shells

Attackers have been exploiting two zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to gain root access, deploy web shells, and infiltrate internal networks. Citrix confirmed the active exploitation of both flaws and released security updates to address them.

ZeroDay News ·

Source: BleepingComputer

Attackers have been exploiting two zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to gain root access, deploy web shells, and infiltrate internal networks. Citrix confirmed the active exploitation of both flaws and released security updates to address them.

The campaign reportedly began in early September, impacting organizations in North America and Europe across various sectors including government, financial services, education, legal, and professional services. Cybersecurity firms privately alerted organizations to the unpatched vulnerabilities and, in some cases, advised them to shut down affected appliances before Citrix publicly disclosed the issues.

CVE-2026-88771 is an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled.

Observations of exploitation attempts date back to September 24, three days prior to Citrix's public disclosure. One observed attack originated from IP address 149.104.78.141 and involved attempts to modify `/bin/sh` to provide a root shell and install a password-protected PHP web shell at `/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver`. The attackers also tried to modify `/etc/httpd.conf` to redirect requests for seemingly innocuous CSS files, such as `receiver.min.css`, to open the hidden PHP web shell.

Further analysis indicates that exploits for CVE-2026-88772 bypass authentication and cause the NetScaler Packet Processing Engine (NSPPE) to terminate unexpectedly, granting attackers root-level access. This is believed to occur through specially malformed or fragmented record headers that induce heap memory boundary corruption within the packet engine, leading to arbitrary shellcode execution with root privileges on the underlying FreeBSD platform.

Post-exploitation activities include the installation of PHP web shells and modifications to the NetScaler web server configuration. Attackers configured the web server to process non-executable file extensions as PHP, allowing web shells to operate from directories typically housing NetScaler client software. In some instances, `.deb` files were configured to execute as PHP, while in others, `.sig` files were used, and requests for `.ico` images under `/vpn/media/` were mapped to malicious PHP files. This allowed malicious web shell requests to appear as legitimate image or CSS file requests while executing commands via PHP functions like `shell_exec()` or `eval()`. Some web shells returned fake HTTP 404 responses to further mask their activity.

Threat actors deployed two previously undocumented malware families: WHIPSHOT and SLAPSHOT. WHIPSHOT is a PHP web shell disguised as a Debian package and stored in the NetScaler VPN scripts directory. It functions as an HTTP proxy for SLAPSHOT, extracting Base64-encoded data from HTTP request headers and forwarding it to the tunneling malware. WHIPSHOT can also check for SLAPSHOT's presence and launch embedded Python payloads.

SLAPSHOT is a Python-based TCP tunneling tool designed to bridge the compromised NetScaler appliance with internal devices, facilitating lateral movement within the network. It receives commands from WHIPSHOT, opens connections to internal hosts, transmits and receives data, and closes sessions. This proxy functionality was used in at least one observed intrusion for manual reconnaissance and credential theft. SLAPSHOT can also self-terminate after periods of inactivity, complicating detection.

While initial exploitation grants root privileges, commands executed by the web shells would typically run under a lower-privileged account associated with the NetScaler web servers. To maintain persistent root access, attackers modified permissions on `/bin/sh` by asserting the setuid bit, ensuring that commands run with elevated privileges. Attackers also rebooted NetScaler appliances or restarted the web server to apply configuration changes.

NetScaler ADC and Gateway appliances are attractive targets due to their internet exposure and their placement at the edge of internal networks, often lacking the protection of Endpoint Detection and Response (EDR) software.

Organizations are strongly advised to install the latest Citrix security updates to address both vulnerabilities. For those unable to patch immediately, disabling DTLS where operationally feasible and blocking inbound UDP/443 upstream when DTLS is not required can mitigate CVE-2026-88772. However, these mitigations do not protect against CVE-2026-88771.

Defenders should also inspect NetScaler appliances for signs of compromise, including unauthorized PHP handlers or aliases in `httpd.conf`, suspicious `.deb` or `.sig` files containing PHP code, unusual HTTP 404 responses, unexpected NSPPE crashes, and the presence of `/tmp/.uxdport` or `/tmp/.uxdlock` files associated with SLAPSHOT. Checks should also be performed for modifications to `/bin/sh` to run with setuid root permissions and for suspicious Python processes launched with `nohup` or containing Base64-encoded payloads.

vulnerabilities in this storyCVE-2026-88771CVE-2026-88772
citrixnetscalerzero-dayvulnerabilityexploitation
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.