Mandiant: two Citrix NetScaler zero-days exploited since September
Since early September 2026, an unknown threat actor has been exploiting two zero-days in Citrix NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772). Mandiant described a campaign using PHP webshells, the SLAPSHOT tunneling tool and credential theft; Citrix released fixed builds 14.1-73.37 and 13.1-64.23.
- NetScaler ADC and Gateway affected; fixes are 14.1-73.37 and 13.1-64.23
- Attack uses WHIPSHOT webshell, SLAPSHOT tunnel and credential theft
- Mandiant does not attribute the campaign to a specific actor
- Targets are organizations in North America and Europe, including utilities and industry
Read next
Security