Overview
- Security firms Mandiant and Google Threat Intelligence Group say attackers began exploiting NetScaler flaws in early September and remained undetected for weeks, allowing broad access to internet-facing appliances.
- Two critical bugs are confirmed exploited: CVE-2026-88772 is a DTLS-related heap overflow in the NetScaler packet engine that can run shellcode before login, and CVE-2026-88771 allows unauthenticated command execution on default configurations.
- Researchers observed post-exploitation tooling and persistence techniques including WHIPSHOT (a PHP web shell), SLAPSHOT (a Python tunneler), Apache config changes that run .deb/.sig as PHP, .ico-to-.sig redirects, and making /bin/sh setuid to keep root access.
- Citrix released fixed builds on Sept. 27 and national CERTs (CISA, NCSC-NL, ACSC) urge urgent patching plus forensic steps: capture memory and logs before upgrades, inventory customer-managed versus Citrix-managed instances, disable DTLS or block inbound UDP/443 where feasible, and rotate keys and credentials after mitigation.
- Dozens to more than 100 organizations across government, finance, education, telecom and professional services report likely impact, and defenders should assume compromise, expect follow-on opportunistic abuse, and prepare for both credential theft and possible VPN outages from denial-of-service exploitation.