Google Warns of Hackers Actively Exploiting Citrix 0-Day Vulnerabilities to Deploy Web Shells

Google Warns of Hackers Actively Exploiting Citrix 0-Day Vulnerabilities to Deploy Web Shells

By Abinaya
Publication Date: 2026-09-30 16:50:00

Google has warned that threat actors are actively exploiting two critical Citrix NetScaler zero-day vulnerabilities to gain root access, install stealthy web shells, and move into victim networks.

The activity has affected organizations in North America and Europe, including government, financial services, technology, education, legal, and professional-services sectors.

Mandiant Consulting and Google Threat Intelligence Group (GTIG) said the campaign has been active since at least early September 2026.

The attackers are abusing CVE-2026-88772, a critical memory-overflow flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, alongside CVE-2026-88771, an unauthenticated remote code execution vulnerability caused by improper input validation.

Citrix assigned both flaws a CVSS score of 9.5 and confirmed active exploitation. CVE-2026-88772 affects appliances with Datagram Transport Layer Security enabled, which is enabled by default on VPN virtual servers.

Google…