Mass exploitation of Citrix NetScaler: What we currently know
3 hours ago
- Government agencies and critical infrastructure were targeted in attacks exploiting two critical Citrix NetScaler vulnerabilities (CVE-2026-88771 and CVE-2026-88772) with severity 9.5.
- The flaws enable remote code execution, memory overflow, and other impacts; DTLS must be enabled for one vulnerability.
- Attacks date back to at least August–September, affecting dozens of organizations across North America and Europe in sectors like government, healthcare, finance, and education.
- Threat actors are believed to be state-sponsored, using custom webshells (e.g., Whipshot) and a Python tunneler (Slapshot) for reconnaissance and credential theft.
- Citrix released patches for affected versions; organizations urged to apply upgrades immediately.
- Patching alone may not remove post-exploitation access; rotation of credentials and revocation of active sessions are recommended.
- Mitigation measures include isolating NetScaler, disabling DTLS, blocking inbound UDP/443, and auditing downstream infrastructure.