Skip to main content

Share story

Security

Attackers exploit two NetScaler flaws to install persistent web shells

Attackers exploit two NetScaler flaws to install persistent web shells Image: Primary
Attackers are exploiting CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and Gateway appliances to execute code and install web shells for persistent access, SOC Prime reports. The flaws permit remote code execution and memory corruption. Unit 42 identified activity before disclosure, including version fingerprinting and two web shell delivery techniques. One exploitation chain drops .deb packages; another uses poisoned logs in Perl scripts. Researchers also recovered a PHP web shell that encrypts command communications with RC4. SOC Prime recommends upgrading Citrix software, isolating vulnerable systems where possible and reviewing Apache configurations for unauthorized changes. Suspected compromises warrant collecting system snapshots and logs and investigating unexpected outbound connections.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from socprime.com and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Products
AI Products

SoftBank seeks up to $100 billion from Gulf investors for AI

SoftBank Group Corp. is seeking to raise as much as $100 billion from investors in the Gulf region to help finance an expansion of the company's investments in artificial intelligence, the Financial Times has reported....

AI Science
AI Science

Nullify preprint reports selective LLM forgetting without weight updates

Researchers report in a preprint that Nullify, a method designed to suppress specific memorized information in large language models, matches or surpasses established forgetting baselines on TOFU and MUSE while preserving model ut...

AI Science
AI Science

Preprint reports schema-free generation of valid enterprise test data

Researchers report in an arXiv preprint that their Generalist Populator agent generated enterprise data with 100% constraint satisfaction and 0.88 average marginal fidelity across ten simulated environments without accessing datab...

AI Science
AI Science

Preprint reports task-completion gains from agent-generated interfaces

Researchers report in an arXiv preprint that training an agent to generate interactive interfaces improved a 4B model's Pass@3 task-completion score from 9.33% to 58.00%. Their GenUI-Harness pairs an agent that retrieves informati...