Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
Google’s Mandiant and GTIG reported ongoing exploitation of NetScaler zero-days CVE-2026-88771 and CVE-2026-88772, which attackers used to gain root access and deploy web shells. The campaign, active since at least early September, affected organizations across multiple sectors in North America and Europe, with more than 100 victims potentially impacted. #CVE-2026-88771 #CVE-2026-88772 #NetScaler #Mandiant #GTIG #WHIPSHOT #SLAPSHOT

Keypoints

  • Citrix patched two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772.
  • Attackers used the flaws for unauthenticated remote code execution and root access.
  • The campaign targeted government, finance, education, legal, and professional services organizations.
  • Mandiant found new malware components named WHIPSHOT and SLAPSHOT in the attacks.
  • GreyNoise and others observed exploitation before disclosure, and more than 100 victims may have been affected.

Read More: https://www.securityweek.com/government-finance-orgs-targeted-in-weeks-long-netscaler-zero-day-attacks/