NetScaler CVE-2026-88772 zero-day tied to state hackers

NetScaler CVE-2026-88772 zero-day tied to state hackers

Attackers exploited CVE-2026-88772, one of two recently disclosed Citrix NetScaler zero-days, in targeted intrusions starting in early September. The initial wave was likely the work of "advanced and suspected state-sponsored threat actors," according to Mandiant CTO Charles Carmakal.

Mandiant and Google Threat Intelligence Group (GTIG) know of dozens of affected organizations in North America and Europe. Carmakal said victims include organizations in the government, financial services, education, telecommunications, and legal and professional services sectors.

Two flaws, one confirmation

In the days before September 27, 2026, organizations around the world were notified of active attacks that appeared to involve an unknown flaw in Citrix NetScaler ADC and Gateway appliances. On that date, Citrix confirmed that two vulnerabilities had been exploited as zero-days: CVE-2026-88771 and CVE-2026-88772.

Both let remote attackers run code on vulnerable devices, but under different conditions. CVE-2026-88771 works against any appliance running a default configuration. CVE-2026-88772 can only be exploited when DTLS configuration is enabled.

Security firms and independent researchers have already described attacks on CVE-2026-88771. The new findings from Mandiant's incident responders and GTIG focus on the second bug. The researchers say they first spotted exploitation of CVE-2026-88772 in the wild in late September, but the activity goes back to at least early September.

Inside the attacks

According to the researchers, exploiting CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE), which gives the attacker root-level access.

GTIG does not have the exploit code. Frontline telemetry suggests that "transmitting specially malformed or fragmented record headers induces heap memory boundary corruption within the packet engine, diverting control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform."

After getting in, the attackers took slightly different routes. In some cases, the first web shell modified httpd.conf, the configuration file of the Apache web server built into the appliance. The change made the server treat .deb files as PHP scripts, so the attackers could quietly stage web shells with misleading file extensions in /netscaler/gui/vpn/scripts/linux.

"In other intrusions, the threat actor implemented a stealthier configuration hook that disguised web shell execution as image requests," the researchers noted.

The attackers used several web shells to run commands and stay on the compromised devices. They also deployed a TCP tunneling tool that the researchers named SLAPSHOT. It let them proxy traffic from the appliance into internal networks.

Patching won't remove attackers

Carmakal expects broad, opportunistic exploitation of both flaws by a range of threat actors.

For CVE-2026-88771, this has already started. Widespread "spray and pray" attacks followed the online publication of technical details and a proof of concept. Wider abuse of CVE-2026-88772 has likely begun as well: on Tuesday, watchTowr researchers published an analysis of the flaw together with a "Detection Artefact Generator."

Google's researchers have released detailed guidance on threat hunting, containment and remediation. All organizations running NetScaler ADCs and Gateways should follow it. Carmakal stressed that upgrading to a fixed version will not remove attackers who are already inside. It also does nothing about the risk from stolen credentials.

The Bigger Picture

This case follows a familiar pattern. A capable, likely state-backed group quietly uses a flaw in an internet-facing appliance for weeks. Disclosure comes. Public research follows within days, and opportunistic criminals move in. The gap between "targeted zero-day" and "mass exploitation" appears to keep shrinking. That leaves defenders very little time between learning about a bug and seeing it used widely.

The timeline is the main point for readers. If exploitation began in early September, any exposed NetScaler device with DTLS enabled should be treated as possibly compromised, not just unpatched. Carmakal's warning that updating does not evict intruders or fix stolen credentials suggests that compromise assessments, hunting for web shells and tunneling tools, and credential resets matter as much as the patch itself.

It also fits a wider trend of edge devices becoming a favored entry point. We recently covered a Check Point VPN flaw that is also under active attack. It is worth watching whether more victims come forward in the sectors Mandiant named, and whether follow-on intrusions trace back to access gained through these appliances.