LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
CVE-2026-88772

Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)

Suspected state-sponsored threat actors have been exploiting a zero-day vulnerability in NetScaler Application Delivery Controllers (ADCs) and Gateways, identified as CVE-2026-88772, since at least early September 2026. This flaw, along with a related vulnerability, CVE-2026-88771, allows for remote code execution on affected appliances. Citrix confirmed the active exploitation of both…

ZeroDay News ·

Source: Help Net Security

Suspected state-sponsored threat actors have been exploiting a zero-day vulnerability in NetScaler Application Delivery Controllers (ADCs) and Gateways, identified as CVE-2026-88772, since at least early September 2026. This flaw, along with a related vulnerability, CVE-2026-88771, allows for remote code execution on affected appliances. Citrix confirmed the active exploitation of both vulnerabilities on September 27, 2026, following reports of attacks involving a possible zero-day.

Mandiant and Google Threat Intelligence Group (GTIG) have identified dozens of organizations impacted across North America and Europe. These include entities in government, financial services, education, telecommunications, and legal and professional services sectors. While CVE-2026-88771 affects all devices running a default configuration, CVE-2026-88772 is exploitable only when DTLS configuration is enabled.

Mandiant's incident responders and GTIG researchers detailed their findings on the CVE-2026-88772 attacks, noting that they first flagged in-the-wild exploitation in late September 2026, with activity dating back to early September. The exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE), granting initial root-level access.

Analysis of telemetry suggests that transmitting specially malformed or fragmented record headers induces heap memory boundary corruption within the packet engine. This diverts control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform.

In some instances, after gaining access, attackers modified the `httpd.conf` file, which configures the appliance's built-in Apache web server. This modification caused the web server to process `.deb` files as PHP scripts, enabling attackers to covertly stage web shells with deceptive file type extensions in the `/netscaler/gui/vpn/scripts/linux` directory. Other intrusions involved a stealthier configuration hook that disguised web shell execution as image requests.

Attackers utilized various web shells for command execution and persistence on compromised devices. They also deployed a TCP tunneling tool, dubbed SLAPSHOT by researchers, to proxy traffic into internal networks.

Cybersecurity experts anticipate broad and opportunistic exploitation of both CVE-2026-88772 and CVE-2026-88771 by a range of threat actors. Widespread exploitation of CVE-2026-88771 has already commenced following the public release of technical details and a proof-of-concept. Similarly, wider exploitation of CVE-2026-88772 is likely to have started, especially after researchers shared an analysis of the flaw and a detection artifact generator.

Organizations running NetScaler ADCs and Gateways are advised to follow detailed threat hunting, containment, and remediation guidance provided by Google's researchers. Simply upgrading to a fixed version is insufficient to remove attackers from compromised systems and does not address the risk associated with stolen credentials.

vulnerabilities in this storyCVE-2026-88772
vulnerabilityzero-daynation-statefinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.

CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…