#6
The Hacker News
general
October 01, 2026 at 04:35 UTC
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
By [email protected] (The Hacker News)
AI Summary
Threat actors exploited a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) across multiple customer environments, deploying web shells mapped to CSS-like URLs and creating superuser accounts to persist access. LevelBlue's THOR team confirmed the activity targeted government and financial sector organizations over a weeks-long campaign, making unpatched NetScaler appliances an active battleground.
Relevance score: 87.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →