Google’s Mandiant and Threat Intelligence Group (GTIG) have published details on attacks exploiting the NetScaler zero-days that Citrix patched over the weekend.
The vulnerabilities are tracked as CVE-2026-88771 and CVE-2026-88772, and they affect NetScaler ADC and NetScaler Gateway instances. Attackers can exploit these critical flaws for unauthenticated remote code execution.
Before Citrix released patches, government cybersecurity agencies and security firms took the rare step of urging administrators to disconnect affected NetScaler appliances from the internet immediately while zero-day exploitation investigations were ongoing.
Mandiant and GTIG, whose report focuses on the exploitation of CVE-2026-88772, spotted attacks in late September. However, their investigation found that the zero-day campaign has been “ongoing since at least early September.”
The attacks likely impacted organizations in North America and Europe. These organizations are in the government, financial services, education, legal, and professional services sectors.
The attackers exploited the vulnerability to gain root access to NetScaler ADC and Gateway appliances. They then changed the appliance’s web server configuration so they could plant web shells and run them with root privileges.
Mandiant found previously unseen malware in the attacks, including a PHP web shell named WHIPSHOT and a Python-based tunneling tool named SLAPSHOT. The two work together to give the attackers a path from the compromised appliance into the victim’s internal network.
According to Mandiant, the tools enable internal reconnaissance, lateral movement and credential theft. In at least one intrusion, the hackers used the tunnel to manually explore the internal network and steal credentials.
Mandiant also saw signs that the threat actor may be managing similar web shells in multiple compromised environments.
Mandiant CTO Charles Carmakal noted that dozens of organizations have been hit, including by suspected state-sponsored threat actors.
“We expect broad and opportunistic exploitation of CVE-2026-88772 and CVE-2026-88771 by a variety of threat actors in the near term,” Carmakal warned.
Cybersecurity expert Kevin Beaumont reported being aware of more than 100 victim organizations as of Tuesday, noting that the attacks appear to be part of an espionage campaign.
Security firm WatchTowr, one of the first to confirm in-the-wild exploitation, has released technical details on both CVE-2026-88772 and CVE-2026-88771.
Threat intelligence company GreyNoise observed zero-day exploitation attempts on September 24, several days before the flaws were disclosed and patched.
“The [malicious cyber actor] attempted to set both the Set User ID (setuid) and Set Group ID (setgid) bits on /bin/sh to obtain a root shell and install a password-protected webshell that accepts communication by the cookie value sent by the adversary. This may be to avoid persisting their commands in web logs,” GreyNoise explained.
Palo Alto Networks reported that there had been roughly 50,000 potentially exposed NetScaler instances as of September 27.
Related: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
Related: Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’
Related: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks


