~Malpedia~
Autonomous C2 mass-exploits vulnerable NetScaler devices for root access and agent deployment.
-
IOCs: 45[.]143[.]130[.]195, /tmp/[.]nsagent, /s/<bid>
-
#CVE202688771 #Malware #ThreatIntel

~Malpedia~
Autonomous C2 mass-exploits vulnerable NetScaler devices for root access and agent deployment.
-
IOCs: 45[.]143[.]130[.]195, /tmp/[.]nsagent, /s/<bid>
-
#CVE202688771 #Malware #ThreatIntel
eSentire tracks four clusters behind CVE-2026-88771 exploitation, planting NetScaler web shells and backdoor accounts. Learn how to detect them.
#CVE202688771 #CitrixNetScaler #WebShell #ZeroDay #Platypus #eSentire #EdgeSecurity #CyberSecurity
Discover how hackers exploit CVE-2026-88771 in Citrix NetScaler to hide PHP web shells as CSS files, granting remote access and compromising networks.
~Cybergcca~
Actively exploited NetScaler flaws enable remote code execution and appliance compromise.
-
IOCs: CVE-2026-88771, CVE-2026-88772
-
#CVE202688771 #CVE202688772 #ThreatIntel
Citrix flags a NetScaler SAML authentication issue as patched NetScaler appliances reboot after CVE-2026-88771 attacks. Check your config.
#Citrix #NetScaler #SAML #CVE202688771 #CVE202688772 #ZeroDay #Vulnerability
I'm seeing Sliver being deployed onto netscalers
#netscaler #exploit #cve #catalinwhenwillyou-repostmyawesomeposts
Attackers exploit Citrix NetScaler zero-day CVE-2026-88772 for root access, then hide WHIPSHOT web shells and a SLAPSHOT tunneler. Patch now.
#CitrixNetScaler #ZeroDay #CVE202688772 #CVE202688771 #WHIPSHOT #SLAPSHOT #Mandiant #CyberSecurity
~Spiderlabs~
Critical NetScaler flaws enable unauthenticated RCE and are actively exploited worldwide.
-
IOCs: CVE-2026-88771, CVE-2026-88772
-
#CVE202688771 #CVE202688772 #ThreatIntel
@mandiant.com
Active exploitation enables root access, WHIPSHOT web shells and SLAPSHOT tunneling.
-
IOCs: CVE-2026-88772, CVE-2026-88771, WHIPSHOT
-
#CVE202688771 #CVE202688772 #ThreatIntel
Public PoC for CVE-2026-88771 is fueling mass exploitation of internet-facing Citrix NetScaler ADC and Gateway devices, with log poisoning, webshells, and over 100 victim orgs tracked. #Citrix #NetScaler #CVE202688771
🔴 Citrix NetScaler: two zero-days under active attack
CVE-2026-88771 and CVE-2026-88772 can lead to RCE on vulnerable NetScaler ADC/Gateway systems. Both are rated CVSS 9.5 and added to CISA KEV.
#CVE #CVE202688771 #CVE202688772 #Citrix #NetScaler #CyberSecurity
CVE-2026-88771 is a Citrix NetScaler command injection exploited in the wild. Details and a PoC are public. Patch NetScaler to 14.1-73.37 now.
#Citrix #NetScaler #CVE202688771 #CommandInjection #ZeroDay #ExploitedInTheWild #PoC #PatchNow
Two critical Citrix NetScaler zero-day flaws, rated 9.5 on CVSS 4.0, are under attack. See the fixed builds and how to respond.
#Citrix #NetScaler #ZeroDay #CVE202688771 #CVE202688772 #RCE #VPN #CISAKEV
~Watchtowr~
Actively exploited unauthenticated command injection enables root RCE on default NetScaler configurations.
-
IOCs: CVE-2026-88771
-
#CVE202688771 #Citrix #ThreatIntel
@sophossecurity.bsky.social
Critical NetScaler flaws enable unauthenticated RCE and are actively exploited.
-
IOCs: CVE-2026-88771, CVE-2026-88772
-
#CVE202688771 #CVE202688772 #ThreatIntel
~Cybergcca~
CISA added two Citrix NetScaler CVEs to KEV; apply updates.
-
IOCs: CVE-2026-88771, CVE-2026-88772
-
#CVE202688771 #Citrix #ThreatIntel
~Certeu~
Citrix confirms active exploitation of two unauthenticated NetScaler RCEs; patch immediately and assess internet-facing appliances.
-
IOCs: CVE-2026-88771, CVE-2026-88772
-
#CVE202688771 #Citrix #ThreatIntel