Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
Mandiant links weeks-long NetScaler ADC/Gateway zero-day exploitation to suspected state actors, hitting 100+ government, finance, and legal organizations.
Mandiant and Google Threat Intelligence Group report that attacks exploiting CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and Gateway have been ongoing since at least early September, granting attackers root access. Victims include dozens of organizations in government, financial services, education, legal, and professional services across North America and Europe, with Kevin Beaumont counting more than 100 victims. Attackers planted a new PHP web shell called WHIPSHOT and the SLAPSHOT Python tunneling tool for internal reconnaissance, lateral movement, and credential theft. Palo Alto Networks estimated roughly 50,000 potentially exposed NetScaler instances as of September 27, and broad opportunistic exploitation is expected.
- CVE-2026-88771/88772 unauthenticated RCE in NetScaler ADC/Gateway exploited since early September
- New WHIPSHOT web shell and SLAPSHOT tunneling tool enable reconnaissance and credential theft
- Kevin Beaumont reports 100+ victim organizations; suspected espionage campaign
- GreyNoise saw exploitation attempts September 24, before disclosure; ~50,000 exposed instances
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article486 words · extracted from securityweek.com · click to collapse
Google’s Mandiant and Threat Intelligence Group (GTIG) have published details on attacks exploiting the NetScaler zero-days that Citrix patched over the weekend.
The vulnerabilities are tracked as CVE-2026-88771 and CVE-2026-88772, and they affect NetScaler ADC and NetScaler Gateway instances. Attackers can exploit these critical flaws for unauthenticated remote code execution.
Before Citrix released patches, government cybersecurity agencies and security firms took the rare step of urging administrators to disconnect affected NetScaler appliances from the internet immediately while zero-day exploitation investigations were ongoing.
Mandiant and GTIG, whose report focuses on the exploitation of CVE-2026-88772, spotted attacks in late September. However, their investigation found that the zero-day campaign has been “ongoing since at least early September.”
The attacks likely impacted organizations in North America and Europe. These organizations are in the government, financial services, education, legal, and professional services sectors.
The attackers exploited the vulnerability to gain root access to NetScaler ADC and Gateway appliances. They then changed the appliance’s web server configuration so they could plant web shells and run them with root privileges.
Advertisement. Scroll to continue reading.
Mandiant found previously unseen malware in the attacks, including a PHP web shell named WHIPSHOT and a Python-based tunneling tool named SLAPSHOT. The two work together to give the attackers a path from the compromised appliance into the victim’s internal network.
According to Mandiant, the tools enable internal reconnaissance, lateral movement and credential theft. In at least one intrusion, the hackers used the tunnel to manually explore the internal network and steal credentials.
Mandiant also saw signs that the threat actor may be managing similar web shells in multiple compromised environments.
Mandiant CTO Charles Carmakal noted that dozens of organizations have been hit, including by suspected state-sponsored threat actors.
“We expect broad and opportunistic exploitation of CVE-2026-88772 and CVE-2026-88771 by a variety of threat actors in the near term,” Carmakal warned.
Cybersecurity expert Kevin Beaumont reported being aware of more than 100 victim organizations as of Tuesday, noting that the attacks appear to be part of an espionage campaign.
Security firm WatchTowr, one of the first to confirm in-the-wild exploitation, has released technical details on both CVE-2026-88772 and CVE-2026-88771.
Threat intelligence company GreyNoise observed zero-day exploitation attempts on September 24, several days before the flaws were disclosed and patched.
“The [malicious cyber actor] attempted to set both the Set User ID (setuid) and Set Group ID (setgid) bits on /bin/sh to obtain a root shell and install a password-protected webshell that accepts communication by the cookie value sent by the adversary. This may be to avoid persisting their commands in web logs,” GreyNoise explained.
Palo Alto Networks reported that there had been roughly 50,000 potentially exposed NetScaler instances as of September 27.
Related: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
Related: Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’
Related: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks