Skip to content

Banks, gov’ts, telcos hit by hackers amid escalating NetScaler incident

42,000 instances may be exposed as attacks mount

Banks, gov’ts, telcos hit by hackers amid escalating NetScaler incident

A sustained threat campaign against NetScaler users remains ongoing – as details emerge over the sophisticated malware being deployed on enterprise systems. 

A brace of zero days (now allocated CVE-2026-88771 and CVE-2026-88772) are being exploited in the ubiquitous enterprise gateway and application delivery controllers.

Citrix published a security advisory and patches on September 27. 

Censys sees 42,000 internet-facing NetScaler ADC or NetScaler Gateway instances. 

Mandiant said on September 29 the “threat actor has deployed multiple PHP web shells and a tunneler malware to proxy traffic into the victim organization’s network facilitating internal reconnaissance, lateral movement and credential harvesting.”

(Citrix NetScaler products often sit between the public internet and an organisation's network and applications – handling critical jobs like load balancing and SSL/TLS termination, secure remote access and VPN access, depending on configuration.) 

Mandiant CTO Charles Carmakal said he expects initial exploitation by a state-aligned threat group to escalate into widespread, opportunistic attacks by cybercriminals. 

Disclosed by JPMorgan's threat team

The vulnerabilities were disclosed by JPMorgan’s growing "XOR" vulnerability research team

The bank was understood by The Stack to be angry at the pace with which Citrix patched – and the fact that exploitation began before the issuance of a patch. 

We could not immediately independently confirm a disclosure timeline. 

(Want to share more details in confidence? Signal @Targett.11) 

JPMorgan was previously also credited by Citrix with a string of CVEs it pushed patches for in June this year. (America’s largest bank is taking an increasingly proactive stance in trying to identify vulnerabilities in software it uses across its stack. Earlier this year it moved the firm’s head of penetration testing into a third-party oversight team focused on scrutinising supplier practices and product security.) 

You’re all exposed!

The Dutch NCSC-NL warned that CVE-2026-88771 affects all NetScaler ADC and Gateway deployments; it requires no additional functionality or configuration. 

(Many other recent NetScaler vulnerabilities required the appliance to be configured as a Gateway or AAA virtual server. CVE-2026-88772, meanwhile, is exploitable when DTLS is enabled. That is the default on NetScaler’s VPN virtual servers.) 

Citrix emphasised that applying a software update “does not remove potential compromise artifacts or prove that exploitation did not occur before the update. 

“If compromise is suspected or confirmed, Citrix recommends deploying a new, updated NetScaler instance rather than relying on the update as a cleanup or remediation mechanism.” Guidance on that can be found in this support article.

Whipshot and Slapshot malware

Google Mandiant said it has seen custom malware it is dubbing “WHIPSHOT” (a PHP web shell) and “SLAPSHOT” (a Python proxy/tunneler) dropped on victims’ systems.

Mandiant CTO Charles Carmakal posted on LinkedIn that it has seen organisations across North America and Europe hacked “in the government, financial services, education, telecommunications, and legal and professional services sectors”

The cybersecurity company noted that “broad internet isolation or strict IP allow-listing on NetScaler Gateways can create significant disruption for organizations supporting remote workforces through Citrix Virtual Apps and Desktops (formerly XenApp and XenDesktop)” and organisations should, clearly, act “based on their risk tolerance, evidence of compromise, and operational requirements…”

CISOs + engineering + The Board

Arcanum Security’s Jason Haddix noted that security leadership needs to evolve fast in a landscape in which the number of exploited vulnerabilities is surging, saying “you have to shift from risk-management programs to add engineering programs.”

“If you aren't already comfortable integrating with your organization's engineering teams, get comfortable fast. You should be building a security engineering team that can actually help with development of security features and pipeline automation, you're going to need this ASAP…. You would not believe the amount of security leaders I talk to where it is absolutely not table stakes,” he posted on X this week.

Teams need to pivot fast to drilling incident response with “rehearsed playbooks and SOPs [standard operating procedures] for real exploitation scenarios or impacts. 

“Drill via tabletops, with real artifacts, and get used to roles, responsibilities, emergency comms ops, etc… Start talking to your execs and boards about this shift. Cite the recent AI labs incidents if you need to. Work hard to position cybersecurity FROM a gate -> TO security that moves at engineering speed. Don't forget to beat the drum about product downtime and how that materially impacts the organization when it weighs cybersecurity against the overall budget planning,” Haddix concluded. 

The Dutch NCSC separately commented on September 24 that “cybersecurity is not an IT problem that can be solved somewhere in a basement or datacentre. It is a broad organisational issue, a governance issue and, ultimately, a societal issue.”

Warning of the growing risk and pace of attacks augmented by AI capabilities, it added in a multi-agency call-to-arms (other signatories included the General Intelligence and Security Service) that organisations must “prioritise cybersecurity in the boardroom” and make more funding available for security, adding “it is not defensible that attacks should take place because the fundamentals are not in order.”

Join peers following The Stack on LinkedIn

Add The Stack on Google