Hasty Briefsbeta

Bilingual

Mass exploitation of Citrix NetScaler: What we currently know

3 hours ago
  • Government agencies and critical infrastructure were targeted in attacks exploiting two critical Citrix NetScaler vulnerabilities (CVE-2026-88771 and CVE-2026-88772) with severity 9.5.
  • The flaws enable remote code execution, memory overflow, and other impacts; DTLS must be enabled for one vulnerability.
  • Attacks date back to at least August–September, affecting dozens of organizations across North America and Europe in sectors like government, healthcare, finance, and education.
  • Threat actors are believed to be state-sponsored, using custom webshells (e.g., Whipshot) and a Python tunneler (Slapshot) for reconnaissance and credential theft.
  • Citrix released patches for affected versions; organizations urged to apply upgrades immediately.
  • Patching alone may not remove post-exploitation access; rotation of credentials and revocation of active sessions are recommended.
  • Mitigation measures include isolating NetScaler, disabling DTLS, blocking inbound UDP/443, and auditing downstream infrastructure.