ThreatPaper
Assessed, Not Confirmed

The .deb web shells were dropped through the CVE-2026-88772 DTLS bug

Assessment

Unit 42 groups its pre-disclosure .deb web shell activity under CVE-2026-88772 DTLS exploitation, and Mandiant's report, which concerns CVE-2026-88772, describes the same .deb and .sig persistence. But eSentire reports a .deb-variant web shell installed on 5 September through CVE-2026-88771 log injection, with the same command-handling code as an .ico/.sig variant. The persistence method is shared across both bugs, so a .deb web shell on an appliance does not by itself say which vulnerability was used, and defenders cannot rely on DTLS controls alone.

Where this claim appeared

Palo Alto Networks Unit 42 · 2026-09-30

https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772: three weeks of exploitation before the patch

Think this assessment is wrong? Report an error.