chiprook
← Security
SecurityOctober 3, 2026, 22:19

Mandiant: two Citrix NetScaler zero-days exploited since September

Since early September 2026, an unknown threat actor has been exploiting two zero-days in Citrix NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772). Mandiant described a campaign using PHP webshells, the SLAPSHOT tunneling tool and credential theft; Citrix released fixed builds 14.1-73.37 and 13.1-64.23.

Mandiant: two Citrix NetScaler zero-days exploited since September
#Citrix#NetScaler#Mandiant
Read next
Security

Citrix discloses eight NetScaler vulnerabilities, two already exploited

Security

Citrix NetScaler Exploit Drops Web Shells, Steals Config Data

Security

Exploit details for Citrix NetScaler CVE-2026-88772 reveal pre-auth shellcode path

Security

CISA orders feds to patch exploited Citrix NetScaler flaws by Wednesday