Hispasec•September 30, 2026•🇪🇸Translated from Spanish

Hackers Exploit Two Critical Citrix NetScaler Zero-Days to Deploy Web Shells and Enable Lateral Movement

Threat actors are actively exploiting two critical zero-day vulnerabilities in Citrix NetScaler appliances to gain unauthenticated remote code execution, deploy stealthy web shells, and move laterally across compromised networks.

The vulnerabilities, identified as CVE-2026-88771 and CVE-2026-88772, both carry a CVSS v4.0 score of 9.5. CVE-2026-88771 stems from improper input validation and affects default deployments of NetScaler ADC and NetScaler Gateway. CVE-2026-88772 results from a memory overflow that can lead to RCE or denial of service when DTLS is enabled, a setting active by default on many VPN vServers.

Attackers have moved beyond proof-of-concept exploits. They install password-protected PHP web shells and modify web server configurations so that files with seemingly harmless extensions such as .css or image files are processed as PHP scripts. This technique hinders manual detection and allows malicious payloads to blend with legitimate resources.

Additional persistence techniques include setting the setuid bit on /bin/sh to grant root privileges to commands executed through the web shell. Observed artifacts include the file /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver, suspicious Alias or AliasMatch directives in httpd.conf, and Python processes launched with nohup alongside files such as /tmp/.uxdport and /tmp/.uxdlock.

The campaign has been linked to the WHIPSHOT PHP web shell and the SLAPSHOT TCP tunneling tool written in Python. Citrix has issued patches for NetScaler ADC 13.1 before 13.1-64.23 and 14.1 before 14.1-73.37, along with corresponding NetScaler Gateway builds and FIPS/NDcPP variants. CISA has added both CVEs to its Known Exploited Vulnerabilities catalog and set a September 30, 2026 deadline for federal agencies.

Related articles

Security NEXT•Vulnerabilities & Exploits

Critical Vulnerability CVE-2026-12342 Allows Remote Code Execution in SailPoint IdentityIQ

SailPoint has disclosed a critical vulnerability in its identity management product IdentityIQ that stems from insufficient input validation in the web service API. The flaw, identified as CVE-2026-12342, permits an attacker on an adjacent network to execute arbitrary code on the IdentityIQ server without requiring authentication. The vulnerability received a CVSSv3.1 base score of 9.6 and is rated Critical. SailPoint published a security advisory on September 28, 2026, and has released patches for all supported affected versions. The company also plans to include the fix in future patch levels. The issue affects the processing of content sent to the web service API, where improper validation allows malicious input to trigger code execution.

BoletimSec•Vulnerabilities & Exploits

WatchGuard Patches Critical API Flaws in Access Points Allowing Unauthenticated Command Execution

WatchGuard has released firmware version 3.4.8 to address three vulnerabilities affecting its access points, two of which are rated critical. The most severe issues, CVE-2026-86102 and CVE-2026-101891, both scored 9.3 on the CVSS scale and reside in the internal API management service. These flaws permit unauthenticated attackers with network access to execute arbitrary shell commands or bypass access controls without requiring any credentials or valid sessions. A third vulnerability, CVE-2026-87969 with a CVSS score of 8.6, involves command injection through the command-line diagnostic interface but requires authenticated administrator privileges. All firmware versions from 1.0 through 3.4.7 are impacted. The vulnerabilities were disclosed on September 28 with no evidence of active exploitation or public proof-of-concept code available at the time. A compromised access point could serve as an internal foothold for further network attacks due to its visibility into corporate traffic.

AntiMalware•Vulnerabilities & Exploits

Spectre Variant Returns: Branch Target Reuse Attack Extracts Root Password Hash from Linux Memory

Researchers from VUSec and Scuola Superiore Sant’Anna have disclosed Branch Target Reuse, a new Spectre v2 variant that exploits stale branch predictor entries in modern CPUs. The attack targets JIT compilers that generate and reuse executable code at runtime, allowing speculative execution of instructions from previously freed memory regions. On Intel systems with existing mitigations enabled, the researchers demonstrated extraction of the root password hash from the Linux kernel in minutes. Practical proof-of-concept exploits were developed against the Linux kernel, while PoCs were also prepared for Firefox and tested on GraalVM. The issue affects Intel, AMD, and Arm processors, although exploitation success depends on the specific JIT environment and predictor state. Defenses have already been merged into the Linux kernel and GraalVM, while Mozilla continues work on site isolation. The findings highlight that Spectre-class issues remain relevant as long as processors rely on aggressive speculative execution.

Habr•Vulnerabilities & Exploits

EASM Uncovers Forgotten Perimeter Assets Including 11-Year-Old Servers Invisible to Standard Scanners

EASM solutions continuously discover external attack surfaces by starting from public data such as company names, domains, WHOIS records, Certificate Transparency logs, and internet-wide scanners like Shodan and Censys. Unlike traditional vulnerability scanners that only check assets from a predefined list, EASM maps unknown shadow IT including forgotten test servers, abandoned marketing subdomains, exposed APIs, and cloud buckets left open to the internet. The technology follows the same reconnaissance path used by attackers and has become essential for mature vulnerability management programs after years of being considered exotic. Major vendors including Palo Alto Networks Cortex Xpanse, CyCognito, Qualys, Rapid7, and Tenable now lead the market, while Russian providers such as Positive Technologies PT EASM, BI.ZONE EASM, and CyberOK PenOps have grown rapidly since 2022. Without an established process for prioritization and remediation, EASM implementations risk generating overwhelming alert volumes rather than reducing risk. The approach is now viewed as a core component of Continuous Threat Exposure Management (CTEM) frameworks.