Citrix published fixes on Sunday 27 September 2026 for a set of NetScaler ADC and Gateway vulnerabilities, two of which were already being exploited. CVE-2026-88772 corrupts heap memory in the packet processing engine through malformed DTLS record headers and yields unauthenticated root code execution on the appliance. CVE-2026-88771 is an unauthenticated remote code execution flaw through input validation. Both score 9.5. CISA added them to its exploited-vulnerabilities catalogue the same day. Mandiant’s analysis, published two days later, traces exploitation to early September; CyberScoop dates it to at least 3 September.
Shadowserver counted more than 20,000 exposed instances and Palo Alto Networks’ scanning about 50,000. Mandiant described dozens of compromised organisations in North America and Europe across government, financial services, technology, education, legal and professional services, with telecom added by other reporting.
What The Intruders Did Once They Had Root
The tooling is custom. A PHP web shell Mandiant calls WHIPSHOT hides its command channel in Base64 inside HTTP headers. A Python tunneler, SLAPSHOT, carries traffic onward. Persistence used the appliance’s package-signature handling and a setuid shell. From the appliance the intruders moved into internal networks, ran reconnaissance, stole credentials and scrubbed logs systematically. Mandiant’s warning is the one the corpus has recorded for every edge-device file since 26-0810b: applying the patch closes the door and leaves whoever came through it inside.
Suspected, By The Vendor, Without A Country
Mandiant’s chief technology officer described the operators as advanced and suspected state-sponsored. The company’s own write-up assigns no cluster number and names no country. The evidence for the assessment is the tooling’s novelty, the lateral movement and the discipline of the cleanup. The corpus grades that as a vendor assessment at stated confidence, and files it in this section on the strength of the appliance class and the behaviour rather than any attribution, which does not yet exist.
Three Weeks, Twenty Thousand Appliances
The perimeter appliance is where the corpus keeps finding the long dwell. A NetScaler sits in front of the network, terminates the connection and is trusted by everything behind it. Root on it is root on the front door. Three weeks of exploitation before a fix, against tens of thousands of exposed devices, is the ordinary arithmetic of the class, and the organisations that patched on Monday morning now need the harder work Mandiant describes: assume compromise and look for the shell.
Compiled from the Google Cloud and Mandiant analysis, the CISA alert, the Unit 42 threat brief and contemporaneous reporting, listed below. The disclosure date is given as 27 September by most outlets and 29 September by one. Attribution is a vendor assessment without a named state and is carried as such. Victim organisations are not named. Graded medium. Corrections: corrections@forensicpost.com.
- Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway AppliancesGoogle Cloud / Mandiant
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC and GatewayCISA
- Attackers exploited Citrix NetScaler zero-day for at least three weeks undetectedCyberScoop
- Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772Palo Alto Networks Unit 42