Skip to content
Tech News
← Back to articles

Citrix NetScaler zero-day exploited to plant web shells since early September

read original more articles
GoKawiil Brief

Mandiant and other security firms say attackers began exploiting an unpatched Citrix NetScaler flaw, tracked as CVE-2026-88772, in early September to install custom web shells and tunneling malware, gain root access, steal credentials, and move into internal networks. Victims span government, financial services, education, legal, and professional services organizations in North America and Europe. Citrix disclosed two related zero-days, CVE-2026-88771 and CVE-2026-88772, on Sunday and released patches after researchers including GreyNoise and watchTowr flagged active exploitation.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

The gap between initial exploitation in September and public disclosure and patching this week suggests attackers had weeks of unmitigated access to internet-facing NetScaler appliances, a scenario that could let them establish persistent footholds before defenders even knew a flaw existed. GreyNoise's detection of a specific web shell installation technique indicates the campaign was methodical rather than opportunistic, which may complicate remediation for organizations that assume patching alone resolves the threat.

Key Takeaways

Source: bleepingcomputer.com, 2026-09-29

Published there as: “Hackers exploit Citrix NetScaler zero-day to deploy web shells”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.