MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-29 · via BleepingComputer

Attackers Actively Exploit Citrix NetScaler Vulnerabilities to Establish Web Shell Access

Image via BleepingComputer
Image via BleepingComputer

Cybersecurity researchers detected active exploitation of two previously unknown Citrix NetScaler remote code execution vulnerabilities affecting government, financial, and education sectors across North America and Europe. The attackers deployed custom web shells, tunneling malware, and gained root-level access to compromised appliances beginning in early September. Citrix released patches for both vulnerabilities following public disclosure, with researchers recommending defensive hunting for suspicious files that indicate successful exploitation attempts.

Expanded Detail

The discovered vulnerabilities represent two distinct weaknesses in Citrix's NetScaler appliances. One flaw permits unauthenticated attackers to execute code remotely on all ADC and Gateway models, while the second involves memory corruption tied to DTLS protocol functionality. Once inside compromised systems, adversaries systematically established persistent access through hidden web shells, disguised malicious files as legitimate system components, and modified web server configurations to mask their presence from standard detection methods.

Mandiant's investigation revealed attackers targeted organizations across multiple critical sectors during a coordinated campaign spanning at least three weeks before public disclosure. The attackers employed sophisticated post-exploitation techniques, including credential theft and lateral movement into internal networks, suggesting coordinated threat actors rather than opportunistic exploitation.

Context

Organizations relying on Citrix NetScaler appliances for network access and security may face significant operational and security risks until systems are patched. Government agencies, financial institutions, and educational organizations potentially exposed could experience data breaches, service disruptions, or compromised infrastructure. The multi-week window between initial exploitation and public disclosure suggests many organizations may remain unaware of compromise, underscoring the challenges enterprises face detecting advanced persistent threats within critical network infrastructure components.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Citrix patches two actively exploited NetScaler zero-day RCE flaws · Cybersecurity
Citrix Issues Emergency Fixes for Two Actively Exploited NetScaler Zero-Days · Cybersecurity
CISA sets Wednesday deadline for federal agencies to fix actively exploited Citrix NetScaler bugs · Cybersecurity
Critical Citrix NetScaler Flaws Grant Attackers Unrestricted Network Access · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Hackers exploit Citrix NetScaler zero-day to deploy web shells.” Browse more stories.