Citrix NetScaler zero-day mass exploitation; Cisco SD-WAN added to KEV
Citrix NetScaler zero-day mass exploitation and Cisco SD-WAN KEV: patch, isolate, hunt web shells, rotate credentials.
- Attackers are mass-exploiting a critical Citrix NetScaler ADC/Gateway zero-day (CVE-2026-88772, CVSS 9.5; related reporting cites CVE-2026-88771) to deploy WHIPSHOT/SLAPSHOT web shells and gain root.
- CISA also added Cisco Catalyst SD-WAN Manager CVE-2026-76504 to its Known Exploited Vulnerabilities catalog, confirming active exploitation.
- Any organization running internet-facing NetScaler or SD-WAN management interfaces should patch or isolate, hunt for web shells, and rotate credentials.
What to do now
- Inventory every internet-facing Citrix NetScaler ADC/Gateway and Cisco Catalyst SD-WAN Manager instance; record versions, exposure, and management access paths.
- Apply Citrix and Cisco patches immediately. If patching is not possible within hours, remove the appliance from direct internet access, restrict management to trusted IP ranges, enforce MFA, and disable unnecessary features.
- Hunt for indicators: WHIPSHOT/SLAPSHOT web shells, unexpected processes, new admin accounts, configuration edits, root-level activity, and unusual outbound traffic. Review logs from late September 2026 onward.
- Rotate credentials, certificates, API keys, and session tokens that may have transited affected appliances. Isolate suspected systems, preserve forensic evidence, and rebuild from known-good state.
- Segment management planes from user and server networks, enable detailed logging and EDR behavioral detections, and monitor CISA, Citrix, and Cisco advisories for updated guidance.
Related items
- Hackers exploit Citrix NetScaler zero-day to deploy web shells
- NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)
- Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services
- Bitget hacked via zero-day in third-party security products
- WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign
- Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
- Cisco warns of new SD-WAN zero-day exploited in attacks
- CISA Adds One Known Exploited Vulnerability to Catalog