Desk live·
ForensicPost
Nation-state/Edge devices/File 26-0927

Citrix NetScaler Zero-Days Were Exploited for Three Weeks Before the Patch, With Root Access

Exploitation of CVE-2026-88772 dates to at least 3 September. Citrix patched and CISA listed it on Sunday 27 September. Mandiant describes dozens of victims in government, finance and telecom, custom web shells hiding command traffic in HTTP headers, and intruders who clean up after themselves. Patching, it warns, does not evict them.

Constructed geometry · not a chart of case data
TargetCitrix NetScaler operators
ActorSuspected state-sponsored (vendor)
S. Rosler10 min readConfidence: medium4 sources reviewed

Citrix published fixes on Sunday 27 September 2026 for a set of NetScaler ADC and Gateway vulnerabilities, two of which were already being exploited. CVE-2026-88772 corrupts heap memory in the packet processing engine through malformed DTLS record headers and yields unauthenticated root code execution on the appliance. CVE-2026-88771 is an unauthenticated remote code execution flaw through input validation. Both score 9.5. CISA added them to its exploited-vulnerabilities catalogue the same day. Mandiant’s analysis, published two days later, traces exploitation to early September; CyberScoop dates it to at least 3 September.

Shadowserver counted more than 20,000 exposed instances and Palo Alto Networks’ scanning about 50,000. Mandiant described dozens of compromised organisations in North America and Europe across government, financial services, technology, education, legal and professional services, with telecom added by other reporting.

What The Intruders Did Once They Had Root

The tooling is custom. A PHP web shell Mandiant calls WHIPSHOT hides its command channel in Base64 inside HTTP headers. A Python tunneler, SLAPSHOT, carries traffic onward. Persistence used the appliance’s package-signature handling and a setuid shell. From the appliance the intruders moved into internal networks, ran reconnaissance, stole credentials and scrubbed logs systematically. Mandiant’s warning is the one the corpus has recorded for every edge-device file since 26-0810b: applying the patch closes the door and leaves whoever came through it inside.

Suspected, By The Vendor, Without A Country

Mandiant’s chief technology officer described the operators as advanced and suspected state-sponsored. The company’s own write-up assigns no cluster number and names no country. The evidence for the assessment is the tooling’s novelty, the lateral movement and the discipline of the cleanup. The corpus grades that as a vendor assessment at stated confidence, and files it in this section on the strength of the appliance class and the behaviour rather than any attribution, which does not yet exist.

Three Weeks, Twenty Thousand Appliances

The perimeter appliance is where the corpus keeps finding the long dwell. A NetScaler sits in front of the network, terminates the connection and is trusted by everything behind it. Root on it is root on the front door. Three weeks of exploitation before a fix, against tens of thousands of exposed devices, is the ordinary arithmetic of the class, and the organisations that patched on Monday morning now need the harder work Mandiant describes: assume compromise and look for the shell.

How we reported this

Compiled from the Google Cloud and Mandiant analysis, the CISA alert, the Unit 42 threat brief and contemporaneous reporting, listed below. The disclosure date is given as 27 September by most outlets and 29 September by one. Attribution is a vendor assessment without a named state and is carried as such. Victim organisations are not named. Graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway AppliancesGoogle Cloud / Mandiant
  2. Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC and GatewayCISA
  3. Attackers exploited Citrix NetScaler zero-day for at least three weeks undetectedCyberScoop
  4. Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772Palo Alto Networks Unit 42
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary