Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)
Suspected state-sponsored actors exploited NetScaler zero-day CVE-2026-88772 since early September, affecting dozens of organizations.
Mandiant and Google Threat Intelligence Group say suspected state-sponsored actors have exploited Citrix NetScaler zero-day CVE-2026-88772 since at least early September 2026. Citrix confirmed on September 27 that CVE-2026-88771 and CVE-2026-88772 were exploited for remote code execution; the latter works only when DTLS is enabled and bypasses authentication by crashing the packet engine to gain root on FreeBSD. Dozens of organizations in North America and Europe were hit across government, finance, education, telecommunications, and legal services. Attackers modified httpd.conf, planted web shells, and proxied traffic with a TCP tunnel called SLAPSHOT. Patching does not evict intruders or revoke stolen credentials, and broader opportunistic exploitation is expected.
- CVE-2026-88771 and CVE-2026-88772 both allow remote code execution on NetScaler.
- CVE-2026-88772 needs DTLS and has been exploited since early September 2026.
- Dozens of government, finance, education, telecom, and legal organizations were affected.
- Attackers installed web shells and tunneled internally with the SLAPSHOT tool.
- Upgrading does not remove existing access or stolen credentials.
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article553 words · extracted from helpnetsecurity.com · click to collapse
“Advanced and suspected state-sponsored threat actors” are likely to be behind the initial targeted intrusions that leveraged CVE-2026-88772, one of the two recently disclosed NetScaler vulnerabilities that have been exploited as zero-days, says Mandiant CTO Charles Carmakal.
Mandiant and Google Threat Intelligence Group (GTIG) know of dozens of impacted organizations across North America and Europe, he added, “including in the government, financial services, education, telecommunications, and legal and professional services sectors.”
Two NetScaler zero-days exploited
On September 27, 2026, a few days after organizations around the world began getting notified of active attacks involving a possible zero-day vulnerability in Citrix NetScaler ADCs and Gateways, Citrix confirmed that two flaws had been exploited: CVE-2026-88771 and CVE-2026-88772.
Both allow remote attackers to achieve remote code execution on vulnerable appliances. While the former works on all devices that run a default configuration, the latter is exploitable only if DTLS configuration is enabled.
CVE-2026-88771 exploitation attempts and successes have already been detailed by cybersecurity firms and security researchers, but Mandiant’s incident responders and Google Threat Intelligence Group (GTIG) researchers have now released their own findings on the attacks relying on CVE-2026-88772.
They say that they first flagged in-the-wild exploitation of CVE-2026-88772 in late September 2026 and that the exploitation activity has been ongoing since at least early September.
How the attacks unfolded
“Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access,” they found.
“While Google Threat Intelligence Group does not possess exploit code, analysis of frontline telemetry suggests that transmitting specially malformed or fragmented record headers induces heap memory boundary corruption within the packet engine, diverting control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform.”
In some attacks, after gaining access, the attackers’ initial web shell payload modifies httpd.conf, the configuration file for the Apache web server built into the appliance, so that the web server would handle .deb files as though they were PHP scripts and attackers could covertly stage web shells with deceptive file type extensions in /netscaler/gui/vpn/scripts/linux.
“In other intrusions, the threat actor implemented a stealthier configuration hook that disguised web shell execution as image requests,” the researchers noted.
The attackers used a number of web shells to execute commands and achieve persistence on targeted devices, as well as a TCP tunneling tool (dubbed SLAPSHOT by the researchers), which allowed them to proxy traffic into internal networks.
Patching is not enough
Carmakal says that broad and opportunistic exploitation of CVE-2026-88772 and CVE-2026-88771 by various threat actors is expected.
Widespread “spray and pray” exploitation of the latter has already started after technical details and a PoC have been shared online.
Wider exploitation of the former is likely to have started already, as watchTowr researchers shared an analysis of the flaw and a “Detection Artefact Generator” on Tuesday.
Google’s researchers have shared detailed threat hunting, containment and remediation guidance which all organizations running NetScaler ADCs and Gateways should follow, and Carmakal has made sure to stress that upgrading to a fixed version is not enough to boot the attackers out, and does nothing to address the risk related to stolen credentials.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
