Home / Oct 02, 2026 / Story
0
#6 The Hacker News general October 01, 2026 at 04:35 UTC

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

By [email protected] (The Hacker News)

AI Summary

Threat actors exploited a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) across multiple customer environments, deploying web shells mapped to CSS-like URLs and creating superuser accounts to persist access. LevelBlue's THOR team confirmed the activity targeted government and financial sector organizations over a weeks-long campaign, making unpatched NetScaler appliances an active battleground.

Relevance score: 87.0/100

# More from October 02