Mandiant’s newly published incident evidence shows exploited NetScaler appliances receiving root-level persistence, custom web shells and an internal tunnelling capability, making clean-build verification and compromise assessment inseparable.
What changed
Citrix confirms active exploitation of CVE-2026-88771 and CVE-2026-88772. Mandiant now provides evidence of root access, custom WHIPSHOT and SLAPSHOT malware, credential-focused internal reconnaissance and hunt-ready artefacts, so patch completion alone is not defensible closure. CVE-2026-88771 permits unauthenticated command execution and applies to default customer-managed NetScaler ADC and Gateway deployments.
Public record through 2026-09-30. Source references count citations across published briefings, including repeated sources. Explore the record and its limits →
What We Publish / What We Sell
D
Free · Public
The Daily
Five evidence-backed selections for security leaders, every weekday.
Security.io scores each dimension from 0–100. Exposure reflects deployment reach and privileged network placement; Urgency reflects exploitation tempo and remediation window; Business consequence reflects credential access, persistence and potential interruption. Exposure: 94. Urgency: 98. Business consequence: 93. Focus the chart and use the up and down arrow keys for detail. Source: Security.io editorial assessment based on Citrix, Mandiant and CERT-EU evidence.