Hackers Exploit Citrix NetScaler Zero-Days to Gain Root Access and Deploy Web Shells

Hackers Exploit Citrix NetScaler Zero-Days to Gain Root Access and Deploy Web Shells

By Tamilselvan
Publication Date: 2026-09-30 08:44:00

Threat actors are actively exploiting two critical Citrix NetScaler ADC and NetScaler Gateway zero-day vulnerabilities to gain initial access, establish root-level persistence, deploy disguised PHP web shells, and tunnel into internal victim networks.

Mandiant Consulting and Google Threat Intelligence Group (GTIG) said the campaign targeting CVE-2026-88772 has been active since at least early September and has likely affected organizations in North America and Europe across government, financial services, technology, education, and legal and professional services.

Citrix has also confirmed active exploitation of CVE-2026-88771. Both flaws carry a CVSS v4 score of 9.5.

Hackers Exploit Citrix NetScaler Zero-Days

CVE-2026-88772 is a memory-overflow vulnerability in NetScaler’s DTLS processing that affects appliances with DTLS enabled, a default configuration on VPN virtual servers.

GTIG’s telemetry indicates attackers send malformed or…