By shattered.io
Publication Date: 2026-10-01 14:10:00
The two Citrix NetScaler flaws that shipped without CVE numbers four days ago now have a federal deadline attached to them, and that deadline has already passed. The Cybersecurity and Infrastructure Security Agency added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog on September 27, 2026, assigning both a CVSS score of 9.5 and ordering federal civilian agencies to patch by September 30. That deadline fell on Tuesday. Mandiant and Google Threat Intelligence Group now say the exploitation behind the bugs traces to a suspected state-backed group running custom web shells called WHIPSHOT and SLAPSHOT, according to reporting from Help Net Security and SecurityWeek.



