Citrix NetScaler Zero-Days Exploited; About 50,000 Devices May Remain Exposed
Suspected hackers exploited Citrix NetScaler CVE-2026-88771 and CVE-2026-88772; about 50,000 devices may still be exposed.
DataBreaches.net reports that suspected state-backed hackers exploited two unauthenticated remote-code-execution flaws in Citrix NetScaler ADC and Gateway, CVE-2026-88771 and CVE-2026-88772, both rated CVSS 9.5, as zero-days for weeks before patches existed. The Hacker News, citing LevelBlue's THOR team, instead characterizes CVE-2026-88771 as a pre-authentication command injection of the same score, used to create a superuser named sec_monitor, steal configuration data, map a PHP web shell to CSS-like URLs, and open a reverse shell to 45.141.21.130 on TCP 443. That outlet also says Mandiant and Google's GTIG separately reported dozens of organizations hit through CVE-2026-88772 with WHIPSHOT web shells and the SLAPSHOT Python tunneler, a victim count and tooling detail DataBreaches.net does not give. Both sources agree the flaws are in CISA's Known Exploited Vulnerabilities catalog. Fixed builds cited are 14.1-73.37 and 13.1-64.23, plus FIPS/NDcPP build 13.1-37.279, and federal civilian agencies faced a remediation and forensic-triage deadline of September 30, 2026. About 50,000 devices may still be exposed, and patching alone does not show whether a system was previously compromised.
- CVE-2026-88771 and CVE-2026-88772 affect Citrix NetScaler ADC and Gateway; DataBreaches.net calls both unauthenticated RCE flaws rated CVSS 9.5, while The Hacker News describes CVE-2026-88771 as pre-authentication command injection, also…
- DataBreaches.net says suspected state-backed hackers exploited both as zero-days for weeks before patches, and both are in CISA's Known Exploited Vulnerabilities catalog.
- LevelBlue THOR observed a superuser account named sec_monitor, configuration theft, a PHP web shell mapped to CSS-like URLs, and a reverse shell to 45.141.21.130 on TCP 443.
- Mandiant and Google GTIG reported dozens of organizations hit via CVE-2026-88772 using WHIPSHOT web shells and the SLAPSHOT Python tunneler.
- Fixed builds cited are 14.1-73.37 and 13.1-64.23, plus FIPS/NDcPP build 13.1-37.279.
- Federal civilian agencies had a remediation and forensic-triage deadline of September 30, 2026.
- About 50,000 devices may still be exposed, and patching alone does not show prior compromise.
Coverage timelineoldest first · each row is one article
- · 1d agoCitrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
The Hacker News· 93
LevelBlue details post-exploitation of actively exploited Citrix NetScaler flaw CVE-2026-88771: superuser account creation, PHP web shells, and configuration theft.
- · 1d agoSuspected State Hackers Exploited Citrix NetScaler for Weeks. 50,000 Devices May Still Be Exposed.
DataBreaches.net· 92
Suspected state hackers exploited two Citrix NetScaler zero-days; about 50,000 devices may remain exposed.
Vulnerabilities in this storyAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
| CVE | Vulnerability | CVSS | EPSS |
|---|