Suspected state-sponsored threat actors have been exploiting a zero-day vulnerability in NetScaler Application Delivery Controllers (ADCs) and Gateways, identified as CVE-2026-88772, since at least early September 2026. This flaw, along with a related vulnerability, CVE-2026-88771, allows for remote code execution on affected appliances. Citrix confirmed the active exploitation of both vulnerabilities on September 27, 2026, following reports of attacks involving a possible zero-day.
Mandiant and Google Threat Intelligence Group (GTIG) have identified dozens of organizations impacted across North America and Europe. These include entities in government, financial services, education, telecommunications, and legal and professional services sectors. While CVE-2026-88771 affects all devices running a default configuration, CVE-2026-88772 is exploitable only when DTLS configuration is enabled.
Mandiant's incident responders and GTIG researchers detailed their findings on the CVE-2026-88772 attacks, noting that they first flagged in-the-wild exploitation in late September 2026, with activity dating back to early September. The exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE), granting initial root-level access.
Analysis of telemetry suggests that transmitting specially malformed or fragmented record headers induces heap memory boundary corruption within the packet engine. This diverts control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform.
In some instances, after gaining access, attackers modified the `httpd.conf` file, which configures the appliance's built-in Apache web server. This modification caused the web server to process `.deb` files as PHP scripts, enabling attackers to covertly stage web shells with deceptive file type extensions in the `/netscaler/gui/vpn/scripts/linux` directory. Other intrusions involved a stealthier configuration hook that disguised web shell execution as image requests.
Attackers utilized various web shells for command execution and persistence on compromised devices. They also deployed a TCP tunneling tool, dubbed SLAPSHOT by researchers, to proxy traffic into internal networks.
Cybersecurity experts anticipate broad and opportunistic exploitation of both CVE-2026-88772 and CVE-2026-88771 by a range of threat actors. Widespread exploitation of CVE-2026-88771 has already commenced following the public release of technical details and a proof-of-concept. Similarly, wider exploitation of CVE-2026-88772 is likely to have started, especially after researchers shared an analysis of the flaw and a detection artifact generator.
Organizations running NetScaler ADCs and Gateways are advised to follow detailed threat hunting, containment, and remediation guidance provided by Google's researchers. Simply upgrading to a fixed version is insufficient to remove attackers from compromised systems and does not address the risk associated with stolen credentials.






