Citrix NetScaler zero-day exploited in active attacks to deploy web shells and steal credentials

Mandiant says campaigns hit North American and European government, financial, education and legal organisations since early September

By LineZotpaper
Published
Read Time2 min
Sources2 outlets
Attackers have been exploiting a Citrix NetScaler zero-day since at least early September to deploy custom web shells and tunneling malware, gain root access, steal credentials and spread into internal networks, according to cybersecurity firms Mandiant, GreyNoise and watchTowr. The campaign has reportedly affected organisations in North America and Europe across government, financial services, education, legal and professional services sectors.

The attacks centre on two vulnerabilities that Citrix disclosed on Sunday as CVE-2026-88771 and CVE-2026-88772, which some researchers have dubbed "PitScaler." Citrix confirmed both flaws had been exploited on unmitigated NetScaler deployments and released security updates to address them.

CVE-2026-88771 is an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled.

The campaign first came to light over the weekend, when Citrix administrators reported that IT suppliers, security teams, CERTs and national cybersecurity agencies had privately warned organisations about two unpatched NetScaler zero-days, in some cases advising them to shut down affected appliances. Cybersecurity firm watchTowr later said it had verified reports that both remote code execution flaws were being exploited in the wild and that Citrix was preparing patches.

GreyNoise said it observed a threat actor attempting to exploit a Citrix NetScaler Gateway on September 24, three days before Citrix publicly disclosed the flaws. The attack originated from IP address 149.104.78.141. GreyNoise said the attacker attempted to modify /bin/sh to provide a root shell, install a password-protected PHP web shell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver, and alter /etc/httpd.conf so requests for what appeared to be CSS files, including receiver.min.css, would instead open the hidden web shell.

GreyNoise is not publishing the full exploit for now, but recommends defenders hunt for the .ctxs.receiver file, related Alias or AliasMatch entries in httpd.conf, changes to the permissions of /bin/sh, and connections from the observed source IP.

Mandiant has released a report providing further detail on how CVE-2026-88772 is being exploited, confirming the attacks began in at least early September.

§

Analysis

Why This Matters

  • NetScaler ADC and Gateway appliances sit at the network perimeter and are often trusted entry points for remote access, meaning a root-level compromise can hand attackers a foothold inside government and enterprise networks.
  • The vulnerabilities were exploited before patches existed, and some administrators were advised to shut down affected appliances, underscoring the severity and the pressure on organisations to respond quickly.
  • Attackers stole credentials and established persistence via web shells, raising the risk of follow-on intrusions, data theft or ransomware.

Background

Citrix NetScaler devices are widely used enterprise remote access and application delivery appliances. Such edge devices have repeatedly been prime targets for attackers, since compromising one can bypass perimeter defences. Security researchers have previously given unofficial names to exploited Citrix flaws, and the "PitScaler" label continues that pattern. The current incident stands out because independent firms observed exploitation before Citrix's public disclosure, a sign that defenders were operating without patch guidance for several days.

Key Perspectives

Mandiant and GreyNoise: Active exploitation has been underway since at least early September, with attackers deploying custom web shells and tunneling malware, and Mandiant assessing that organisations in government, financial services, education, legal and professional services across North America and Europe have been affected. Citrix: The company disclosed both vulnerabilities on Sunday, confirmed they had been exploited on unmitigated deployments and has released security updates, while also publishing support guidance for the flaws. watchTowr and other researchers: Verified that both zero-days were being exploited in the wild and highlighted that patches were still being prepared when the warnings emerged, prompting calls for organisations to check for indicators of compromise. Critics and sceptics: The window between private warnings and official patches left administrators with difficult choices, including shutting down critical appliances. There are concerns that organisations which have not yet applied updates or checked for the reported indicators remain exposed.

What to Watch

  • Whether Citrix releases further technical detail on CVE-2026-88772 exploitation as Mandiant and others continue investigating.
  • Adoption of the security updates, and whether additional organisations come forward as victims of the campaign.
  • Whether the attackers behind the observed activity expand targeting to other regions, or whether other threat actors begin using the same exploits now that the flaws are public.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.