Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Citrix Vulnerabilities Exploited by Hackers, Warns Google

Citrix Vulnerabilities Exploited by Hackers, Warns Google

Posted on September 30, 2026 By CWS

Google has issued a warning about active exploitation of two major zero-day vulnerabilities in Citrix NetScaler systems. These vulnerabilities are being leveraged by hackers to gain unauthorized access and install web shells, potentially compromising organizational networks.

The vulnerabilities, affecting entities across North America and Europe, have been identified in critical sectors such as government, finance, technology, education, legal, and professional services. The campaign has been ongoing since early September 2026, according to Mandiant Consulting and Google Threat Intelligence Group (GTIG).

Understanding the Citrix Exploits

The attackers are targeting two specific vulnerabilities: CVE-2026-88772, a critical memory overflow issue in Citrix NetScaler ADC and Gateway appliances, and CVE-2026-88771, a remote code execution flaw due to improper input validation. Both vulnerabilities have been given a CVSS score of 9.5, highlighting their severity.

These vulnerabilities allow attackers to bypass authentication, causing unexpected terminations in the NetScaler Packet Processing Engine (NSPPE) and enabling root-level access to the system. Once inside, attackers alter the configuration of the web server to execute malicious scripts disguised as regular files.

Deployment of Malicious Web Shells

In observed cases, attackers have manipulated .deb packages and .sig signature files to execute PHP code. They have also used icon aliases to disguise web shell executions as harmless file requests. A new PHP web shell identified as WHIPSHOT is being used to embed command-and-control data within legitimate HTTP headers, thus blending malicious activities with normal traffic.

Another tool, a Python-based tunneling tool named SLAPSHOT, has been employed to redirect traffic from compromised devices to internal networks, facilitating further reconnaissance and credential theft.

Protective Measures and Recommendations

Organizations are urged to update their NetScaler systems immediately. Citrix has released fixed versions, including NetScaler 14.1-73.37 and later, and NetScaler 13.1-64.23 and later. Administrators should scrutinize configuration files for suspicious activity and investigate any unusual system behavior as potential compromise indicators.

Security teams should be vigilant for unexpected NSPPE crashes, unusual HTTP requests, and other indicators of compromise. Ensuring endpoint detection coverage for internet-facing appliances is crucial, as these devices provide direct access to sensitive environments.

GreyNoise research indicates that exploitation attempts began even before Citrix publicly disclosed these vulnerabilities, underscoring the urgent need for proactive security measures. Organizations should integrate threat intelligence tools to enhance their security operations and reduce response times.

Cyber Security News Tags:Citrix, Cybersecurity, Exploitation, Google, GTIG, Hackers, Mandiant, NetScaler, network security, security patches, system updates, Vulnerabilities, web shells, zero-day

Post navigation

Previous Post: Google Chrome Update Fixes 32 Security Vulnerabilities
Next Post: Russian Hackers Launch New Phishing Campaign Targeting 100+ Organizations

Related Posts

Storm-1175 Exploits Internet Vulnerabilities in Medusa Attacks Storm-1175 Exploits Internet Vulnerabilities in Medusa Attacks Cyber Security News
North Korean Hackers Attacking Unmanned Aerial Vehicle Industry to Steal Confidential Data North Korean Hackers Attacking Unmanned Aerial Vehicle Industry to Steal Confidential Data Cyber Security News
Linux Battery Utility Flaw Lets Hackers Bypass Authentication and Tamper System Settings Linux Battery Utility Flaw Lets Hackers Bypass Authentication and Tamper System Settings Cyber Security News
PowerShell Exploited in New TASK#STOMP Cyber Intrusion PowerShell Exploited in New TASK#STOMP Cyber Intrusion Cyber Security News
Threat Actors Advertising AI-Enhanced Metamorphic Crypter with Claims of Windows Defender Bypass Threat Actors Advertising AI-Enhanced Metamorphic Crypter with Claims of Windows Defender Bypass Cyber Security News
Apple Resolves Security Flaw in Beats Studio Buds Apple Resolves Security Flaw in Beats Studio Buds Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Hackers Launch New Phishing Campaign Targeting 100+ Organizations
  • Citrix Vulnerabilities Exploited by Hackers, Warns Google
  • Google Chrome Update Fixes 32 Security Vulnerabilities
  • Phishing Campaigns Use MSP360 for Hidden Access
  • Cloudflare Advances Quantum-Safe Internet Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Hackers Launch New Phishing Campaign Targeting 100+ Organizations
  • Citrix Vulnerabilities Exploited by Hackers, Warns Google
  • Google Chrome Update Fixes 32 Security Vulnerabilities
  • Phishing Campaigns Use MSP360 for Hidden Access
  • Cloudflare Advances Quantum-Safe Internet Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark