NetScaler Zero-Day Attacks Hit Government and Finance Sectors
Security researchers reveal that critical NetScaler zero-day vulnerabilities have been actively exploited in stealthy espionage campaigns targeting high-profile sectors across multiple regions.

Severe NetScaler Flaws Trigger Urgent Disconnection Warnings
Google’s Mandiant and Threat Intelligence Group (GTIG) have published comprehensive details regarding attacks that exploit critical NetScaler zero-day vulnerabilities. Tracked as CVE-2026-88771 and CVE-2026-88772, these security flaws affect NetScaler ADC and NetScaler Gateway instances, allowing attackers to execute unauthenticated remote code execution. Before Citrix released official software patches, government cybersecurity agencies and prominent security firms took the rare and drastic step of urging network administrators to immediately disconnect affected NetScaler appliances from the internet while active investigations unfolded.
While Mandiant's specific report focuses heavily on the exploitation of CVE-2026-88772, observations indicate that the underlying zero-day campaign has been ongoing since at least early September. The targeted organizations primarily span North America and Europe, encompassing critical industries such as government, financial services, education, legal, and professional services sectors.
Technical Mechanics of the Zero-Day Campaign
During the intrusions, threat actors successfully exploited the vulnerabilities to acquire root-level access to the targeted NetScaler ADC and Gateway appliances. Once inside, they modified the core web server configuration to seamlessly plant web shells that operate with elevated root privileges. Security research firms like WatchTowr provided early technical validation of the in-the-wild exploitation activity, detailing the precise methods utilized to breach the perimeters.
Concurrently, threat intelligence provider GreyNoise observed active zero-day exploitation attempts against infrastructure starting on September 24, days before public disclosure and patching occurred. According to GreyNoise analysts, malicious actors attempted to configure specific execution bits on shell utilities to secure root access and plant password-protected web shells designed to accept cookie-based communication values to bypass standard web logging.
Novel Malware Arsenal: WHIPSHOT and SLAPSHOT
Mandiant's analysis uncovered previously unseen malware variants deployed explicitly during these operations. The custom toolset features a PHP-based web shell designated as WHIPSHOT and a Python-powered tunneling utility known as SLAPSHOT. Working in tandem, these malicious components provide intruders with a reliable path from the compromised edge appliance deep into the victim's internal enterprise network.
The implementation of these tools facilitates thorough internal reconnaissance, lateral movement, and aggressive credential theft. In at least one documented intrusion, malicious actors leveraged the established network tunnel to manually traverse the internal environment, explore connected systems, and harvest sensitive credentials.
Scope of Compromise and State-Sponsored Espionage
Mandiant CTO Charles Carmakal warned that dozens of organizations have suffered direct compromises, with indications pointing toward suspected state-sponsored threat actors orchestrating the incursions. Security expert Kevin Beaumont similarly reported tracking upwards of 100 victim organizations, characterizing the widespread operations as part of a targeted espionage campaign.
Data gathered from Palo Alto Networks emphasized the massive scale of the potential threat surface, revealing that roughly 50,000 NetScaler instances remained potentially exposed to the internet shortly before the patches were deployed. Security researchers continue to analyze telemetry from these incidents to understand the full breadth of the attacks.
Sources
- SecurityWeekGovernment, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks