SECURITYWEEK reports that government and finance organisations have been targeted in weeks-long exploitation of Citrix NetScaler zero-days. The flaws, CVE-2026-88771 and CVE-2026-88772, affect NetScaler ADC and NetScaler Gateway and enable unauthenticated remote code execution. Before patches were issued over the weekend, authorities urged admins to disconnect affected appliances from the internet during ongoing investigations.
Mandiant and GTIG’s analysis, focused on CVE-2026-88772, found campaigns active from at least early September and continuing into late September, with impacts concentrated in North America and Europe across government, financial services, education, legal and professional services sectors.
The attackers reportedly gained root access, altered web server configurations to plant web shells and run them with root privileges. Mandiant identified previously unseen malware, including a PHP web shell named WHIPSHOT and a Python-based tunnelling tool named SLAPSHOT, which together facilitated internal reconnaissance, lateral movement and credential theft.
Observers noted that the threat was likely broad and opportunistic, with dozens of organisations affected and indications of state-sponsored involvement in some cases. Security firms WatchTowr and GreyNoise documented in-the-wild exploitation and early probing, while Palo Alto Networks’ Unit 42 estimated around 50,000 potentially exposed NetScaler instances as of 27 September. Citrix subsequently released patches to mitigate the vulnerabilities.