⚠️ Region Alert: UAE/Middle East
Citrix has reported zero-day exploitation of CVE-2026-88771 and CVE-2026-88772 in NetScaler Application Delivery Controller (ADC) and Gateway devices. These critical vulnerabilities, both carrying a CVSS score of 9.5, allow for remote code execution (RCE) and memory overflows. Threat actors have been observed leveraging these flaws to deliver sophisticated web shells and establish persistent access within targeted organizations prior to public disclosure.
Technical analysis reveals advanced tactics including DTLS exploitation to drop .deb web shells and a three-stage command injection chain utilizing log poisoning. Attackers disguised malicious PHP scripts as legitimate-looking CSS assets and modified Apache configurations to ensure execution. Organizations are urged to update to the latest NetScaler versions immediately, as over 50,000 instances were identified as potentially exposed during initial telemetry scans.
Top comments (0)