Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)

Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)
Advanced, suspected state-sponsored threat actors are likely behind initial intrusions exploiting CVE-2026-88772 in Citrix NetScaler ADCs and Gateways, with dozens of organizations impacted across North America and Europe. Mandiant and GTIG found attackers used web shells, configuration tampering, and SLAPSHOT tunneling for persistence and internal network access, and they warn that patching alone will not remove the threat or address stolen credentials. #CVE-2026-88772 #CVE-2026-88771 #CitrixNetScaler #Mandiant #GTIG #SLAPSHOT

Keypoints

  • Threat actors exploited two Citrix NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772.
  • CVE-2026-88772 enabled authentication bypass and root-level access on vulnerable appliances.
  • Attackers deployed web shells and modified configuration files to maintain persistence.
  • Some intrusions used stealthy hooks to disguise web shell execution as image requests.
  • SLAPSHOT TCP tunneling was used to proxy traffic into internal networks.

Read More: https://www.helpnetsecurity.com/2026/09/30/cve-2026-88772-netscaler-exploitation-zero-day/