chiprook
← Security
SecurityOctober 1, 2026, 11:35

Citrix NetScaler Exploit Drops Web Shells, Steals Config Data

Threat actors are exploiting a critical pre-authentication command injection flaw in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and steal configuration data. LevelBlue's THOR team observed the activity across multiple customer environments.

Citrix NetScaler Exploit Drops Web Shells, Steals Config Data
#Citrix#NetScaler
Read next
Security

Exploit details for Citrix NetScaler CVE-2026-88772 reveal pre-auth shellcode path

Security

NetScaler zero-day exploitation escalates into mass attacks

Security

CISA orders feds to patch exploited Citrix NetScaler flaws by Wednesday

Security

CVE-2026-65660: Two-Stage SharePoint Attacks Attempt Web Shell Deployment