Hackers exploit Citrix NetScaler zero-day to deploy web shells

Hackers exploit Citrix NetScaler zero-day to deploy web shells
Attackers exploited Citrix NetScaler CVE-2026-88772 and CVE-2026-88771 zero-days to deploy web shells, tunneling malware, steal credentials, and move deeper into internal networks. Mandiant and GreyNoise say the campaign affected organizations across North America and Europe, with persistent post-exploitation tactics including root access abuse and the use of WHIPSHOT and SLAPSHOT. #Citrix #NetScaler #CVE-2026-88771 #CVE-2026-88772 #Mandiant #GreyNoise #WHIPSHOT #SLAPSHOT

Keypoints

  • Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 were exploited in the wild.
  • Attackers used custom web shells and tunneling malware to gain root access and steal credentials.
  • Mandiant linked the campaign to organizations in North America and Europe across multiple sectors.
  • The malware families WHIPSHOT and SLAPSHOT enabled proxying, tunneling, and internal network access.
  • Defenders should patch immediately and inspect NetScaler systems for signs of compromise.

Read More: https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/