ThreatPaper
MalwareCritical

Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772: three weeks of exploitation before the patch

By Sethu Satheesh · 2 Oct 2026 · 18 min read

Threat Actor: Unknown · Target: Citrix NetScaler ADC and Gateway customers in government, finance, education, telecoms and legal sectors

Source: support.citrix.com


Executive Summary

On September 27, 2026, Cloud Software Group published security bulletin CTX697096 for eight vulnerabilities in customer-managed Citrix NetScaler ADC and NetScaler Gateway, and stated that "exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed."1 CISA added both to its Known Exploited Vulnerabilities catalog the same day, said they "can independently enable remote code execution," and reported that "threat actors are actively exploiting these vulnerabilities globally."23 Both carry a CVSS v4.0 base score of 9.5. CVE-2026-88771 affects every NetScaler ADC and Gateway deployment in its default configuration; CVE-2026-88772 requires DTLS, which Citrix notes is enabled by default on VPN virtual servers.1

The bulletin was not the start of the campaign. Mandiant told CyberScoop the earliest known CVE-2026-88772 exploitation occurred September 3, and Google Threat Intelligence Group (GTIG) describes the campaign as "ongoing since at least early September."45 eSentire observed CVE-2026-88771 exploitation from September 5, with a web shell installed and operated that day.6 Palo Alto Networks Unit 42 traced version fingerprinting of NetScaler appliances back to August 21.7 By the time a patch existed, attackers had had roughly three weeks of unannounced access to internet-facing gateways.

No government body or vendor has attributed the activity to a named actor as of October 2, 2026. Mandiant Consulting CTO Charles Carmakal described "advanced and suspected state-sponsored threat actors" and "dozens of impacted organizations across North America and Europe" in government, financial services, education, telecommunications, and legal and professional services.8 GTIG's own published report names the sectors as "likely impacted" and makes no attribution.4 Researcher Kevin Beaumont wrote on September 28 that he was "tracking over 100 victim orgs" and that "it's espionage."9

The finding that matters for defenders is the one every primary source repeats: patching closes the hole, not the intrusion. CISA told organizations to check for compromise before patching and to preserve forensic evidence, because "updates may result in loss of forensic visibility."2 Mandiant's Carmakal wrote that "upgrading alone will not eradicate post-exploitation access or address stolen credentials."8 The web shells recovered by Mandiant, Unit 42, eSentire and LevelBlue live in the appliance's own web-server configuration and file system, and survive an upgrade.47610

Verification of Claims

  1. Claim: CVE-2026-88771 and CVE-2026-88772 were exploited as zero-days before Citrix's September 27 bulletin. → Verified → Citrix states exploitation "has been observed"; CISA added both to KEV citing active exploitation; Mandiant, Unit 42, eSentire, Rapid7 and GreyNoise each describe pre-disclosure activity in their own telemetry.134761112

  2. Claim: Exploitation began in early September 2026. → Verified → Mandiant gives September 3 as the earliest known CVE-2026-88772 exploitation; Unit 42 records .deb web shell requests from September 4; eSentire records CVE-2026-88771 exploitation and an operated web shell from September 5.576 Unit 42's August 21 date is version fingerprinting, not exploitation.7

  3. Claim: The two vulnerabilities are a chain. → Unverified, and contradicted → CISA says each can "independently enable remote code execution."2 Mandiant's report concerns CVE-2026-88772; CERT-EU's and eSentire's concern CVE-2026-88771. CyberScoop reports it is "unclear to what extent the pair of zero-days are linked."41365

  4. Claim: Applying the update does not remove an existing compromise. → Verified → CISA advises checking for compromise and preserving evidence before patching; eSentire states that patching "does not remove any deployed payloads or persistence mechanisms"; Citrix publishes separate steps for a suspected compromise.2614

  5. Claim: The activity is state-sponsored espionage. → Partially verified → This is Mandiant's stated suspicion ("suspected state-sponsored") and Beaumont's assessment, not an attribution. GTIG's published report and CISA's alert make no attribution.8942

  6. Claim: About 50,000 NetScaler appliances were compromised. → Unverified, and a misreading → Unit 42's 50,277 is a count of "exposed instances that could potentially be vulnerable," from Cortex Xpanse telemetry as of September 27. It is not a count of compromised appliances.7 Decryption Digest's headline nonetheless reads "WHIPSHOT Webshell Found on 50,277 Appliances."15

  7. Claim: Dozens of organizations were compromised. → Partially verified → Mandiant says it is "aware of dozens of impacted organizations"; Rapid7 confirms two compromised organizations among its customers; Unit 42 describes compromises at US-based targets. No named organization has disclosed a compromise.8127 Tech Times's "more than 100 organizations already confirmed compromised" restates Beaumont's "tracking over 100," for which no method has been published.169

Timeline

Date Actor Event Source
Aug 21–22, 2026 Unknown Three hosts request NetScaler version-fingerprinting files from a US organization's gateway, then from more than 100 other systems 7
Sept 3, 2026 Unknown Earliest known CVE-2026-88772 exploitation, per Mandiant 5
Sept 4–24, 2026 Unknown Rotating VPS and Cloudflare WARP addresses repeatedly request .deb web shells from the appliance's /vpn/scripts/linux/ folder 7
Sept 5, 2026 Unknown eSentire observes CVE-2026-88771 exploitation; a .deb-variant web shell is installed, operated, and used for data theft and lateral movement 6
Sept 10, 2026 Citrix CVE IDs reserved 11
Sept 20, 2026 Unknown Rapid7 records its earliest CVE-2026-88771 command-injection attempts 12
Sept 21, 2026 Unknown Unit 42 observes a three-stage CVE-2026-88771 chain dropping a PHP web shell on a US target's appliances 7
Sept 24, 2026 Unknown GreyNoise records an exploitation attempt against a Swarm sensor; last .deb web shell request in Unit 42 data 117
Sept 25, 2026 NCSC-NL Dutch NCSC alerts critical infrastructure providers to take immediate measures, including disabling insecure systems 17
Sept 26, 2026 Kevin Beaumont Public post: the zero-day is "real, being used in active attacks," no patch yet 18
Sept 27, 2026 Citrix Bulletin CTX697096 published; fixed builds released 1
Sept 27, 2026 CISA Both CVEs added to KEV with a September 30 due date and forensic triage required; alert issued 2319
Sept 27, 2026 CCCS, NCSC-NL Canadian Centre for Cyber Security alert AL26-024; NCSC-NL public alert 2021
Sept 28, 2026 CERT-EU Publishes its CVE-2026-88771 analysis, begun after staff at two EU bodies found attacker IPs in their NetScaler logs 13
Sept 28, 2026 NCSC UK Urges UK organizations to mitigate; says it is working to understand UK impact 22
Sept 28, 2026 Kevin Beaumont Says he is "tracking over 100 victim orgs" 9
Sept 29, 2026 Mandiant Carmakal posts "dozens of impacted organizations" and suspected state sponsorship 8
Sept 30, 2026 GTIG / Mandiant Publishes WHIPSHOT and SLAPSHOT analysis with indicators and YARA rules 4
Sept 30, 2026 Unit 42, LevelBlue Unit 42 updates its threat brief; LevelBlue publishes a payload that creates a superuser account 710
Oct 2, 2026 CISA Alert updated with a SIGMA detection rule 2

Attack Anatomy

Reconnaissance

Unit 42's earliest observation is not exploitation. On August 21, two hosts requested a stylesheet and a language file from a NetScaler Gateway at a US organization, requests consistent with version fingerprinting; on August 21 and 22 the same two hosts and a third sent identical requests to more than 100 other systems (T1595.002).7

Initial access: two independent bugs

CVE-2026-88772 is a memory overflow in the NetScaler Packet Processing Engine (NSPPE), reachable when DTLS is enabled.1 GTIG states it "does not possess exploit code"; from frontline telemetry, it assesses that malformed DTLS record headers sent over UDP/443 during the pre-authentication handshake corrupt heap memory and give root-level code execution on the underlying FreeBSD system (T1190).4 Successful exploitation left two artifacts: an SSL handshake failure from a DTLSv1.0 client with the reason "Handshake failure-Internal Error", and an NSPPE process termination that the appliance watchdog declined to restart.4

CVE-2026-88771 is, in Citrix's words, an improper-input-validation flaw letting "an unauthenticated attacker to execute arbitrary commands," affecting every deployment by default.1 CERT-EU, eSentire and Unit 42 independently reconstructed it as log injection. The attacker gets two things written into appliance logs: an encoded payload in an HTTP request field, and a crafted login username that imitates an internal packet-engine failure message. A built-in maintenance script that later scans those logs for such failure messages interpolates the matching text into a shell command and runs it as root (T1059.004).1367 Because only the most recent matching line is processed, attackers sent the trigger repeatedly; CERT-EU says this explains the "hammering" its partners saw.13 Login success is not required.6 watchTowr Labs published an independent root-cause analysis.23 This paper does not reproduce the request formats.

Persistence: the web server becomes the backdoor

Every write-up describes the same pattern. The attacker edits /etc/httpd.conf so the appliance's Apache server will execute PHP from files that do not look like scripts, then drops a web shell in a web-reachable path (T1505.003, T1036.008).476

  • GTIG recovered installer shells named on variants of nginstaller and two configuration hooks: one registering .deb files as PHP in /netscaler/gui/vpn/scripts/linux/, a folder that legitimately hosts VPN client packages; and a stealthier one mapping requests for /vpn/media/*.ico to .sig files executed as PHP.4
  • Unit 42's CVE-2026-88771 case placed a hidden file .ctxs.receiver in /var/netscaler/logon/LogonPoint/custom/ and aliased it to receiver.min.css, so command traffic resembles a versioned stylesheet load (T1036.005).7
  • To keep root after the initial exploit, the shells set the setuid bit on /bin/sh and reboot the appliance or restart Apache (T1548.001).47
  • The shells return HTTP 404 to every request, scrub their install path from /etc/crontab, and take commands from Base64-encoded HTTP headers or cookies named to resemble native NetScaler traffic (NSC_*) (T1140).467 Beaumont reports each victim's shell is unique.9

Command and control, lateral movement and collection

GTIG documented WHIPSHOT, a PHP web shell that tunnels traffic, and SLAPSHOT, a Python TCP tunneler it talks to over loopback, writing its port to /tmp/.uxdport and its lock to /tmp/.uxdlock (T1059.006, T1572, T1090.001).4 In at least one intrusion the actor routed traffic through SLAPSHOT "to manually conduct internal reconnaissance and credential theft."4 eSentire saw the actor open sessions on internal virtual desktops and connect back to the appliance over SSH (T1021.004), with web shell responses indicating data exfiltration (T1041).6 Unit 42's recovered nsg64.deb supports command execution, file upload, and chunked file download, with RC4-encrypted traffic.7

Post-disclosure activity is a different population

Unit 42 explicitly separates pre-disclosure activity from what followed, warning that activity after September 27 "might not match the same" indicators because other actors, researchers and scanners joined in.7 LevelBlue's payload, which creates a local sec_monitor account with the superuser role, archives /flash/nsconfig, and attempts to upload it, carries no observation date in its write-up (T1136.001, T1005).10 It should not be assumed to be the original actor's tooling.

Loading diagram...

Threat Actor Profile

Name: Unattributed Aliases: None published Attribution confidence: None formal. Mandiant's CTO describes "advanced and suspected state-sponsored threat actors"; GTIG's report, CISA, CCCS, NCSC UK and NCSC-NL make no attribution as of October 2, 2026.842202221 Motivation: Assessed as espionage by Kevin Beaumont; Mandiant's sector list (government, financial services, legal and professional services) is consistent with that, but neither establishes it.98

Whether one actor exploited both bugs is not established. Unit 42 groups pre-disclosure activity into two clusters by exploit and tooling, and names neither.7 The infrastructure was rented and rotated: one VPS a day from September 4 to 8, Cloudflare WARP exit addresses from September 9 to 11, then a single server making most of the requests from September 15 to 24.7 The tradecraft matches the class GTIG describes in its report: edge devices outside endpoint detection, used as a first hop into the network.4

MITRE ATT&CK techniques (IDs verified live on attack.mitre.org):

ID Technique
T1595.002 Active Scanning: Vulnerability Scanning
T1190 Exploit Public-Facing Application
T1059.004 Command and Scripting Interpreter: Unix Shell
T1059.006 Command and Scripting Interpreter: Python
T1505.003 Server Software Component: Web Shell
T1036.008 Masquerading: Masquerade File Type
T1036.005 Masquerading: Match Legitimate Resource Name or Location
T1548.001 Abuse Elevation Control Mechanism: Setuid and Setgid
T1140 Deobfuscate/Decode Files or Information
T1572 Protocol Tunneling
T1090.001 Proxy: Internal Proxy
T1021.004 Remote Services: SSH
T1041 Exfiltration Over C2 Channel
T1136.001 Create Account: Local Account (post-disclosure payload, per LevelBlue)
T1005 Data from Local System (post-disclosure payload, per LevelBlue)

OPSEC: Fake 404 responses, per-victim shells, shell paths scrubbed from crontab, command channels disguised as native headers and cookies, and file names that pass for client packages, icons and stylesheets.479 Beaumont reports the attackers set up cron jobs to delete artifacts, and that the console checks rely on logs that have often rotated away.24

Technical Indicators

# All indicators as published by the named vendor. Defanged.
fingerprinting_aug_21_22:          # Unit 42
  - 104.248.244[.]66
  - 77.83.199[.]39
  - 78.47.24[.]217
deb_web_shell_requests_sept_4_24:  # Unit 42, attributed by Unit 42 to CVE-2026-88772 activity
  - 66.135.19[.]18
  - 167.99.111[.]203
  - 142.93.85[.]227
  - 104.248.74[.]206
  - 137.184.91[.]207
  - 104.28.247[.]136      # Cloudflare WARP
  - 104.28.215[.]136      # Cloudflare WARP
  - 104.28.215[.]137      # Cloudflare WARP
  - 104.28.247[.]137      # Cloudflare WARP
  - 162.33.178[.]9
  - 193.149.176[.]207
cve_2026_88771_chain_sept_21:      # Unit 42
  - 77.83.199[.]39
  - 78.47.24[.]217
  - 139.180.152[.]138
gtig_infrastructure:               # GTIG
  - 143.198.7[.]94         # scanning and staging
  - 157.254.167[.]12       # exploitation and basic web shell install
exploitation_attempts:
  - 149.104.78[.]208       # Rapid7, Sept 20
  - 149.104.78[.]141       # GreyNoise, Sept 24
post_disclosure_exfil_target:
  - 64.94.85[.]67:443      # LevelBlue, sec_monitor payload
file_hashes:
  - sha256: ae22ef2517b5c0fb47f78745b9cb5260acee0e751b89bcd354640ff8bc8d29ec  # nsg64.deb web shell, Unit 42
host_artifacts:
  - /etc/httpd.conf modified to register .deb, .sig or other non-PHP extensions as PHP, or AliasMatch from /vpn/media/ or /logon/LogonPoint/custom/   # GTIG, Unit 42
  - /var/netscaler/gui/vpn/scripts/linux/*.deb or *.sig containing PHP   # GTIG, eSentire
  - /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver   # Unit 42
  - /bin/sh with setuid bit set   # GTIG, Unit 42
  - /tmp/.uxdport and /tmp/.uxdlock   # SLAPSHOT, GTIG
  - local account sec_monitor with superuser role in /flash/nsconfig/ns.conf   # LevelBlue
log_artifacts:
  - SSL_HANDSHAKE_FAILURE, ClientVersion DTLSv1.0, Reason "Handshake failure-Internal Error"   # GTIG, CVE-2026-88772
  - NSPPE termination followed by pitboss "NOT restarting NSPPE" in /var/log/messages   # GTIG
  - requests to /logon/LogonPoint/Authentication/GetUserName (Unit 42 treats any as anomalous)
domains: none published
note: >
  Citrix distributes its own indicator set through the NetScaler Console IOC scanner;
  GTIG's full set is in a GTI Collection for registered users. Neither is reproduced here.

CISA added both CVEs to the KEV catalog on September 27, 2026, with a due date of September 30 for federal civilian agencies and a "forensic triage" requirement under Binding Operational Directive 26-04.19 The KEV entry for CVE-2026-88771 lists CWE-119 and links the NVD page for CVE-2026-88772; Citrix classifies CVE-2026-88771 as CWE-20, improper input validation.191 CISA's alert was updated on October 2 with a SIGMA rule.2

The Canadian Centre for Cyber Security issued alert AL26-024 on September 27.20 NCSC-NL issued a public alert the same day, updated September 30, after warning critical infrastructure providers on September 25.2117 NCSC UK said on September 28 it was "working to understand the impact" on UK organizations.22 CERT-EU published its own technical analysis.13

No law enforcement action, indictment, sanction or attribution statement tied to this campaign had been published as of October 2, 2026.

Impact Assessment

  • Confirmed: Exploitation of both CVEs before a patch existed, per Citrix and CISA.12
  • Confirmed: Two compromised organizations among Rapid7's customers; compromises at US-based targets in Unit 42 data; web shell installation, data exfiltration and lateral movement in at least one eSentire case.1276
  • Confirmed: Exploitation attempts against NetScaler appliances at the European Court of Auditors and the European Central Bank, which led to CERT-EU's analysis. CERT-EU does not say either was compromised.13
  • Reported: "Dozens of impacted organizations" across North America and Europe (Mandiant); at least 78 targeted organizations (Arctic Wolf, as reported by Cybersecurity Dive); "over 100 victim orgs" tracked (Beaumont, method not published).8179
  • Reported: Dutch hospitals including Frisius MC and Amphia suspended patient-portal access after taking NetScaler-based systems offline, per Cybersecurity Dive.17
  • Estimated: 50,277 exposed and potentially vulnerable instances (Unit 42, as of September 27); more than 20,000 per Shadowserver data cited by Cybersecurity Dive. These are exposure counts, not victim counts.725
  • Unknown: The actor; whether one actor used both bugs; the true number of compromised organizations; what data was taken from any named victim.

Lessons and Defensive Recommendations

For SOC/defenders:

  • Hunt before you patch, and image virtual appliances with memory before rebooting. CISA and Mandiant both warn that the update can destroy forensic evidence.24
  • Check /etc/httpd.conf for any directive that makes non-PHP extensions executable or aliases public web paths into script folders; check /bin/sh for the setuid bit; look for /tmp/.uxdport.4
  • Forward /var/log/messages and the web server logs to your SIEM. GTIG notes several of these detections depend on logs NetScaler does not forward by default.4 Beaumont warns console checks miss activity whose logs have already rotated.24
  • Treat any appliance unpatched in early September as compromised until proven otherwise, as eSentire advises.6

For platform and network teams:

  • If patching is delayed, disable DTLS and block inbound UDP/443 upstream. GTIG is explicit that this addresses CVE-2026-88772 only and does nothing for CVE-2026-88771.4
  • Default-deny outbound traffic from NetScaler appliances, and keep management interfaces off the internet.4
  • After patching, rotate everything the appliance held: admin and local accounts, SSH keys, TLS certificates and private keys, LDAP bind accounts, RADIUS secrets, and API credentials.4

For leadership:

  • The disclosure was not the start of the incident. Budget the response as an investigation of three weeks of possible access, not a patch cycle.46
  • Edge appliances sit outside endpoint detection. GTIG notes such devices made up about half of enterprise-related zero-days in 2025; decide whether your remote-access gateway gets the same logging and integrity monitoring as a server.4

Sources

Footnotes

  1. Cloud Software Group — Citrix NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (CTX697096) — September 27, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8

  2. CISA — Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway — September 27, 2026, updated October 2, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11

  3. CISA — CISA Adds Two Known Exploited Vulnerabilities to Catalog — September 27, 2026 ↩ ↩2 ↩3

  4. Mandiant and Google Threat Intelligence Group — Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances — September 30, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26

  5. CyberScoop — Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected — September 29, 2026 ↩ ↩2 ↩3 ↩4

  6. eSentire — Update: Ongoing Exploitation of Citrix NetScaler ADC and NetScaler Gateway Vulnerabilities — September 29, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15

  7. Palo Alto Networks Unit 42 — Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild — September 30, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25

  8. Charles Carmakal (Mandiant) — LinkedIn post on Citrix NetScaler exploitation — September 29, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8

  9. Kevin Beaumont — Mastodon post, "tracking over 100 victim orgs" — September 28, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8

  10. LevelBlue SpiderLabs — Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators — September 30, 2026 ↩ ↩2 ↩3

  11. GreyNoise — Swarming Against Citrix 0-Day Exploitation — September 28, 2026 ↩ ↩2 ↩3

  12. Rapid7 — Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772 — September 28, 2026 ↩ ↩2 ↩3 ↩4

  13. CERT-EU — Taking 'execute logging' a bit too literally: CVE-2026-88771 — September 28, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6

  14. Cloud Software Group — Steps to Take if NetScaler ADC is Suspected to be Compromised (CTX694799) — accessed October 2, 2026 ↩

  15. Decryption Digest — Citrix NetScaler Backdoors Survive Patching: WHIPSHOT Webshell Found on 50,277 Appliances — October 1, 2026 ↩

  16. Tech Times — Citrix NetScaler Zero-Days Spread Mass Exploitation: Patching Won't Remove Backdoors — September 30, 2026 ↩

  17. Cybersecurity Dive — Mass exploitation of Citrix NetScaler: What we currently know — September 30, 2026 ↩ ↩2 ↩3 ↩4

  18. Kevin Beaumont — Mastodon post, "The Netscaler zero day thing is real" — September 26, 2026 ↩

  19. CISA — Known Exploited Vulnerabilities catalog data feed (entries CVE-2026-88771, CVE-2026-88772) — accessed October 2, 2026 ↩ ↩2 ↩3

  20. Canadian Centre for Cyber Security — AL26-024: Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway — September 27, 2026 ↩ ↩2 ↩3

  21. NCSC-NL — Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu — September 27, 2026, updated September 30, 2026 ↩ ↩2 ↩3

  22. NCSC UK — Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway — September 28, 2026 ↩ ↩2 ↩3

  23. watchTowr Labs — Citrix NetScaler PreAuth Command Injection CVE-2026-88771 — September 28, 2026 ↩

  24. Kevin Beaumont — Mastodon post on NetScaler Console checks and anti-forensics — September 27, 2026 ↩ ↩2

  25. Cybersecurity Dive — Citrix NetScaler exploitation began days before public notification — September 29, 2026 ↩

Topics: #citrix#netscaler#cve-2026-88771#cve-2026-88772#zero-day#web-shell#whipshot#slapshot#edge-device#cisa-kev
Original Incident Report →

Related Research

CVE-2023-46805 and CVE-2024-21887 gave a suspected China-nexus actor unauthenticated code execution on Ivanti VPN gateways from December 2023. Disclosure turned it into 2,100 compromised appliances in a week, a bypassed mitigation and CISA's order to unplug every federal device.

State-SponsoredMalware

GTIG tracked UNC6240 (linked to ShinyHunters) mass-exploiting PeopleSoft's CVE-2026-35273 (CVSS 9.8 unauth RCE). Defenders who blocked /PSEMHUB at a WAF instead of patching were bypassed: the actor requested /%50SEMHUB/, one URL-encoded character, then dropped web shells and the SIDEEYE backdoor.

Data BreachMalwareExtortion & Blackmail

A maximum-severity SonicWall SMA1000 SSRF was exploited as a zero-day three weeks before its July patch. Volexity's UTA0533, a separate credential-harvesting operator, and an INC Ransomware affiliate all piled on — one ran Impacket secretsdump from the appliance to DCSync seven domain controllers.

MalwareState-SponsoredRansomware