Citrix NetScaler exploitation goes from stealth to mass attacks; Apple flaw added to KEV
A NetScaler zero-day is now under widespread exploitation with web shells and root access reported, and CISA has added an actively exploited Apple out-of-bounds write flaw to its Known Exploited Vulnerabilities Catalog.
Help Net Security reported that exploitation of internet-exposed Citrix NetScaler ADC and Gateway deployments has escalated from stealthy zero-day targeting into widespread "spray and pray" exploitation of CVE-2026-88771, fueled by the publication of a root-cause analysis and a proof-of-concept exploit. CVE-2026-88771 carries the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and a base score of 9.8, and CISA lists it as known to be exploited. The affected software is Citrix NetScaler ADC 13.1 up to the fix in 13.1-64.23.
BleepingComputer reported that attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. That CVE has the vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, a base score of 8.1, and is also on CISA's KEV list. The Register reported that the custom malware used in these Citrix zero-day attacks targeted government, banks, and professional services, and noted that two questions remain: who is abusing the CVEs, and why Citrix took so long to disclose. Citrix's security bulletin (CTX697096) covers this cluster of CVEs, which also includes CVE-2026-88777, CVE-2026-88776, and CVE-2026-88775 — each scored 9.8 but not currently on KEV. What to do: apply the fixed release 13.1-64.23 per Citrix's advisory, and treat exposed appliances as potentially compromised — hunt for web shells, unexpected root activity, and lateral movement given the credential theft BleepingComputer describes.
CISA announced it added CVE-2026-86950, an Apple Multiple Products Out-of-Bounds Write Vulnerability, to its KEV Catalog based on evidence of active exploitation. The advisory lists the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, a base score of 8.8, and macOS up to the fix in 15.8.1 as affected. Follow Apple's advisory for the fixed release; CISA's BOD 26-04 requires federal agencies to prioritize rapid remediation of KEV-listed flaws.
In other reporting: BleepingComputer reported that custom variants of OpenAI's ChatGPT, promoted in sponsored Google results, direct users to malicious sites that use ClickFix attacks to deliver RAT malware — a reason to review search-ad-driven lures and endpoint controls. The Hacker News reported that an attacker used stolen passwords of France's tax-administration staff to take tax data on hundreds of thousands of taxpayers and businesses in June and July, and that ANSSI says neither the tax administration nor ANSSI saw the data leave and that the attack was not sophisticated — a reminder to monitor for credential-based access and data egress.
Sources
- The Register — Add one more AI worry to the nightmare scenario: self-replicating prompt injections
- The Record — US Air Force members given over 6 years in prison for cyber theft of more than $2 million
- BleepingComputer — Custom ChatGPTs push ClickFix attacks to deploy RAT malware
- SecurityWeek — OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference
- The Hacker News — French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
- Help Net Security — NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)
- CISA — CISA Adds One Known Exploited Vulnerability to Catalog
- The Record — Controversial spyware firm Paragon to go public by end of year
- BleepingComputer — FBI tells ShinyHunters members to turn themselves in after recent arrest
- The Record — OpenAI apologizes for agents breaching Australian government websites without authorization
- The Register — FBI to ShinyHunters: 'We know how to find you'
- BleepingComputer — Hackers exploit Citrix NetScaler zero-day to deploy web shells
- BleepingComputer — Former US Air Force members sent to prison over BEC attacks
- The Register — Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services