ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Briefings › Citrix NetScaler exploitation goes from stealth to mass attacks; Apple flaw added to KEV
IT SECURITY DESK

Citrix NetScaler exploitation goes from stealth to mass attacks; Apple flaw added to KEV

A NetScaler zero-day is now under widespread exploitation with web shells and root access reported, and CISA has added an actively exploited Apple out-of-bounds write flaw to its Known Exploited Vulnerabilities Catalog.

Help Net Security reported that exploitation of internet-exposed Citrix NetScaler ADC and Gateway deployments has escalated from stealthy zero-day targeting into widespread "spray and pray" exploitation of CVE-2026-88771, fueled by the publication of a root-cause analysis and a proof-of-concept exploit. CVE-2026-88771 carries the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and a base score of 9.8, and CISA lists it as known to be exploited. The affected software is Citrix NetScaler ADC 13.1 up to the fix in 13.1-64.23.

BleepingComputer reported that attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. That CVE has the vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, a base score of 8.1, and is also on CISA's KEV list. The Register reported that the custom malware used in these Citrix zero-day attacks targeted government, banks, and professional services, and noted that two questions remain: who is abusing the CVEs, and why Citrix took so long to disclose. Citrix's security bulletin (CTX697096) covers this cluster of CVEs, which also includes CVE-2026-88777, CVE-2026-88776, and CVE-2026-88775 — each scored 9.8 but not currently on KEV. What to do: apply the fixed release 13.1-64.23 per Citrix's advisory, and treat exposed appliances as potentially compromised — hunt for web shells, unexpected root activity, and lateral movement given the credential theft BleepingComputer describes.

CISA announced it added CVE-2026-86950, an Apple Multiple Products Out-of-Bounds Write Vulnerability, to its KEV Catalog based on evidence of active exploitation. The advisory lists the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, a base score of 8.8, and macOS up to the fix in 15.8.1 as affected. Follow Apple's advisory for the fixed release; CISA's BOD 26-04 requires federal agencies to prioritize rapid remediation of KEV-listed flaws.

In other reporting: BleepingComputer reported that custom variants of OpenAI's ChatGPT, promoted in sponsored Google results, direct users to malicious sites that use ClickFix attacks to deliver RAT malware — a reason to review search-ad-driven lures and endpoint controls. The Hacker News reported that an attacker used stolen passwords of France's tax-administration staff to take tax data on hundreds of thousands of taxpayers and businesses in June and July, and that ANSSI says neither the tax administration nor ANSSI saw the data leave and that the attack was not sophisticated — a reminder to monitor for credential-based access and data egress.

Related