Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Hackers Exploit Citrix NetScaler Zero-Day to Install Web Shells

Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to install web shells and tunneling malware. The attacks reportedly gave them root access, enabled credential theft and helped them move into internal networks.

Mandiant says the activity began at least as early as September and is believed to have affected organizations in North America and Europe. The reported sectors include government, financial services, education, legal and professional services. Citrix disclosed two vulnerabilities, CVE-2026-88771 and CVE-2026-88772, and released security updates. The company confirmed both flaws had been exploited on unmitigated NetScaler deployments. CVE-2026-88771 is an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments. CVE-2026-88772 is a memory overflow flaw that can lead to remote code execution or denial of service when DTLS is enabled.

Mandiant says exploitation of CVE-2026-88772 can bypass authentication and give attackers root-level access. It attributes the access to malformed or fragmented record headers that corrupt memory in the NetScaler packet engine. Researchers also observed attackers disguising PHP web shells as files such as CSS, image, Debian package or signature files by changing web server settings.

Mandiant identified two previously undocumented malware families, WHIPSHOT and SLAPSHOT. WHIPSHOT is a PHP web shell that proxies traffic to SLAPSHOT, a Python-based TCP tunneling tool. The tool can connect the compromised appliance to internal hosts. Mandiant says attackers used the proxy in at least one observed intrusion to conduct reconnaissance and steal credentials.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.