Zero-Day Exploitation of CVE-2026-88771 and CVE-2026-88772 in Citrix NetScaler ADC and Gateway

Eight vulnerabilities, designated CVE-2026-88771 through CVE-2026-88778, affect Citrix NetScaler ADC and Citrix NetScaler Gateway products, with active global exploitation confirmed by threat intelligence partners. Specifically, CVE-2026-88771 and CVE-2026-88772 have been added to the Known Exploited Vulnerabilities (KEV) Catalog as critical zero-day vulnerabilities capable of independently facilitating remote code execution. Due to the complexity and potential downtime associated with updating NetScaler appliances, organizations must urgently assess their exposure, prioritize mitigation, and integrate these vulnerabilities into risk-management protocols. Prior to applying patches, administrators should utilize the NetScaler Console to check for indicators of compromise and preserve forensic evidence, as the update process can permanently erase critical forensic data.

Severity: Critical

Threat Details and IOCs

CVEs: CVE-2019-19781, CVE-2025-6543, CVE-2026-19489, CVE-2026-19490, CVE-2026-8452, CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778
Technologies: Citrix Gateway, Citrix NetScaler, Citrix NetScaler ADC, Citrix NetScaler Gateway, NetScaler ADC, NetScaler Gateway
Victim Industries: Automotive, Cloud Infrastructure, Education, Energy, Financial Services, Government, Healthcare, Higher Education & Research, Information Technology, Insurance, Legal Services, Life Sciences, Manufacturing, Pharmaceuticals, Professional Services, Retail, Technology Hardware, Telecommunications, Transportation
Victim Countries: Netherlands, United States

Mitigation Advice

  • Immediately identify all Citrix NetScaler ADC and Citrix NetScaler Gateway appliances within the environment.
  • Scan all identified Citrix NetScaler appliances for indicators of compromise using the tools and guidance provided by Citrix.
  • If an appliance is suspected to be compromised, isolate it from the network and create a forensic image of the system before applying any patches or configuration changes.
  • Apply the security updates from Citrix to all affected NetScaler ADC and NetScaler Gateway appliances to remediate the vulnerabilities, prioritizing those listed in the CISA KEV Catalog (CVE-2026-88771, CVE-2026-88772).
  • If immediate patching for CVE-2026-88772 is not possible, disable the DTLS protocol on affected NetScaler Gateway VPN virtual servers as a temporary mitigation.
  • If immediate patching for CVE-2026-88778 is not possible, enable the 'Enhanced ISN Generation' feature on affected TCP-based virtual servers as a temporary mitigation.

Compliance Best Practices

  • Implement and maintain a comprehensive, automated asset inventory of all network hardware and software to ensure rapid identification of vulnerable systems in future incidents.
  • Establish a formal vulnerability management program that includes subscribing to vendor and government security alerts, performing regular vulnerability scans, and using a risk-based approach to prioritize patching, with special attention to vulnerabilities in the CISA KEV Catalog.
  • Review and improve network segmentation to create security zones that isolate internet-facing appliances, such as Citrix Gateways, from critical internal servers and user workstations.
  • Develop, test, and maintain a formal Incident Response (IR) plan that includes specific playbooks for compromised network edge devices, covering containment, evidence preservation, eradication, and recovery.

Salt Typhoon Exploits CVE-2024-3400 in Palo Alto PAN-OS and Other Vulnerabilities Targeting Telecom Networks

Nation-state cyber adversaries routinely exploit inherent trust assumptions within legacy telecommunications protocols and edge routing infrastructure to maintain long-term persistence inside carrier networks. The 40-year-old SS7 protocol, which underpins 2G and 3G roaming and SMS, lacks built-in authentication, enabling unauthorized nodes to send Mobile Application Part (MAP) queries to track subscriber locations, intercept voice data, and capture multi-factor authentication keys; similarly, the 4G and 5G Diameter protocol exhibits comparable location-tracking vulnerabilities. At the routing layer, the Border Gateway Protocol (BGP) lacks intrinsic route verification, allowing malicious actors to announce unauthorized prefixes and redirect massive volumes of internet traffic, as demonstrated by China Telecom's 18-minute redirection of 15 percent of internet destinations in 2010. To establish initial access and persistent footholds, state-sponsored groups like Salt Typhoon target backbone and edge routers by exploiting known vulnerabilities—such as CVE-2024-21887/CVE-2023-46805 in Ivanti Connect Secure, CVE-2024-3400 in Palo Alto PAN-OS, and CVE-2023-20273/CVE-2023-20198 in Cisco IOS XE—subsequently deploying GRE tunnels to exfiltrate data. Mitigating these systemic threats requires a multi-layered defense strategy, including the deployment of SS7 and Diameter firewalls, strict vetting of Global Title partners, enforcement of RPKI origin validation, immediate patching of edge devices, and rigorous auditing of network tunnels and configuration baselines.

Severity: Critical

Threat Details and IOCs

Malware: CrowDoor, Demodex, GhostSpider, JumbledPath, ShadowPad, SparrowDoor, SparroWocky
CVEs: CVE-2021-26855, CVE-2023-20198, CVE-2023-20273, CVE-2023-46805, CVE-2024-21887, CVE-2024-3400
Technologies: Cisco IOS XE, Ivanti, Ivanti Connect Secure, Microsoft Exchange Server, Microsoft Windows, Palo Alto Networks PAN-OS
Threat Actors: EarthEstries, FamousSparrow, GhostEmperor, OPERATORPANDA, RedMike, SaltTyphoon, UNC2286
Attacker Countries: China, Iran, Israel, Russia
Attacker IPs: 103[.]169[.]91[.]231, 103[.]199[.]17[.]238, 103[.]253[.]40[.]199, 103[.]7[.]58[.]162, 104[.]194[.]129[.]137, 104[.]194[.]147[.]15, 104[.]194[.]150[.]26, 104[.]194[.]153[.]181, 104[.]194[.]154[.]150, 104[.]194[.]154[.]222, 107[.]189[.]15[.]206, 1[.]222[.]84[.]29, 130[.]94[.]101[.]82, 140[.]99[.]164[.]199, 14[.]143[.]247[.]202, 142[.]171[.]227[.]16, 144[.]172[.]76[.]213, 144[.]172[.]79[.]4, 146[.]70[.]24[.]144, 146[.]70[.]79[.]68, 146[.]70[.]79[.]81, 149[.]104[.]87[.]228, 149[.]104[.]90[.]203, 167[.]88[.]164[.]166, 167[.]88[.]172[.]70, 167[.]88[.]173[.]158, 167[.]88[.]173[.]252, 167[.]88[.]173[.]58, 167[.]88[.]175[.]175, 167[.]88[.]175[.]231, 172[.]86[.]101[.]123, 172[.]86[.]102[.]83, 172[.]86[.]106[.]15, 172[.]86[.]106[.]234, 172[.]86[.]106[.]39, 172[.]86[.]108[.]11, 172[.]86[.]124[.]235, 172[.]86[.]65[.]145, 172[.]86[.]70[.]73, 172[.]86[.]80[.]15, 190[.]131[.]194[.]90, 193[.]239[.]86[.]132, 193[.]239[.]86[.]146, 193[.]43[.]104[.]185, 193[.]56[.]255[.]210, 2001[:]41d0[:]700[:]65dc[::]f656[:]929f, 212[.]236[.]17[.]237, 216[.]238[.]105[.]53, 216[.]238[.]110[.]120, 216[.]238[.]121[.]164, 216[.]238[.]92[.]2, 23[.]227[.]196[.]22, 23[.]227[.]199[.]77, 23[.]227[.]202[.]253, 2a10[:]1fc0[:]7[::]f19c[:]39b3, 37[.]120[.]239[.]52, 38[.]54[.]57[.]17, 38[.]60[.]197[.]55, 38[.]60[.]209[.]106, 38[.]60[.]224[.]235, 38[.]60[.]224[.]51, 38[.]60[.]241[.]127, 38[.]60[.]241[.]193, 38[.]60[.]241[.]65, 38[.]71[.]99[.]145, 43[.]254[.]132[.]118, 45[.]125[.]64[.]195, 45[.]125[.]67[.]144, 45[.]125[.]67[.]226, 45[.]146[.]120[.]210, 45[.]146[.]120[.]213, 45[.]59[.]118[.]136, 45[.]59[.]120[.]171, 45[.]61[.]128[.]29, 45[.]61[.]132[.]125, 45[.]61[.]133[.]157, 45[.]61[.]133[.]31, 45[.]61[.]133[.]61, 45[.]61[.]133[.]77, 45[.]61[.]133[.]79, 45[.]61[.]134[.]134, 45[.]61[.]134[.]223, 45[.]61[.]149[.]200, 45[.]61[.]149[.]62, 45[.]61[.]151[.]12, 45[.]61[.]154[.]130, 45[.]61[.]159[.]25, 45[.]61[.]165[.]157, 5[.]181[.]132[.]95, 59[.]148[.]233[.]250, 61[.]19[.]148[.]66, 63[.]141[.]234[.]109, 63[.]245[.]1[.]34, 74[.]48[.]78[.]116, 74[.]48[.]78[.]66, 74[.]48[.]84[.]119, 77[.]111[.]101[.]40, 85[.]195[.]89[.]94, 89[.]117[.]1[.]147, 89[.]117[.]2[.]39, 89[.]41[.]26[.]142, 91[.]148[.]134[.]115, 91[.]231[.]186[.]227, 91[.]245[.]253[.]99
Attacker Hashes: 3209689e509205ccdb7e49062b7b407ddc23cac1, 33e692f435d6cf3c637ba54836c63373, 44f0a22b143b79fa760bf31e14c8fff714c8a2a1, 52c6646759cf6037bb17466203631c4bd794532f, 8b448f47e36909f3a921b4ff803cf3a61985d8a10f0fe594b405b92ed0fc21f1, 99e7070b5af24a0fe1e6febe5954b03cb385e91f, 9aa9ff61bc63ccab9074fe837f39c980ca9ddc8c, a1abc3d11c16ae83b9a7cf62ebe6d144dfc5e19b579a99bad062a9d31cf30bfe, da692ea0b7f24e31696f8b4fe8a130dbbe3c7c15cea6bde24cccc1fb0a73ae9e, eba9ae70d1b22de67b0eba160a6762d8, f2bbba1ea0f34b262f158ff31e00d39d89bbc471d04e8fca60a034cabe18e4f4
Victim Industries: Business Associations, Defense, Energy, Engineering, Financial Services, Government, Hospitality, International Organizations, Legal Services, Mining, Telecommunications
Victim Countries: Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, United States, Venezuela

Mitigation Advice

  • Immediately patch all Ivanti Connect Secure and Ivanti Policy Secure devices for vulnerabilities CVE-2024-21887 and CVE-2023-46805.
  • Immediately patch all Palo Alto Networks firewalls running PAN-OS with the GlobalProtect feature enabled for vulnerability CVE-2024-3400.
  • Immediately patch all Cisco IOS XE devices for the vulnerability chain involving CVE-2023-20273 and CVE-2023-20198. If patching is not immediately possible, disable the HTTP/HTTPS server feature on affected devices.
  • Perform an urgent vulnerability scan of all internet-facing infrastructure, specifically checking for CVE-2024-21887 (Ivanti), CVE-2024-3400 (Palo Alto), and CVE-2023-20198 (Cisco).

Compliance Best Practices

  • Establish and enforce a formal patch management policy and program for all network infrastructure, with specific service-level agreements (SLAs) for critical, internet-facing devices.
  • Develop and maintain secure configuration baselines for all network devices. Implement a regular audit schedule to compare running configurations against the approved baseline to detect unauthorized modifications.
  • Implement a comprehensive hardware and software asset management program to maintain an accurate inventory of all network devices, their software versions, and their patch status.
  • Implement network segmentation to isolate critical assets and restrict lateral movement between network zones. Ensure that traffic from internet-facing devices is strictly controlled and cannot freely access internal user or server networks.
  • Audit and restrict all network device management interfaces (e.g., SSH, HTTPS, Telnet) to ensure they are not exposed to the public internet. Access should be limited to a secure, internal management network or bastion host.

Microsoft SharePoint RCE Vulnerability CVE-2026-65660 Under Active Exploitation

Active exploitation has been detected targeting CVE-2026-65660, a high-severity remote code execution vulnerability in Microsoft SharePoint that was patched during the August 2026 Patch Tuesday updates. The flaw, initially classified as a medium-severity spoofing issue, is a type-check bypass that allows authenticated attackers with low-level privileges to execute arbitrary code without user interaction, though achieving unauthenticated remote code execution requires chaining it with a separate authentication bypass. Following the public disclosure of technical details by Viettel Security, threat intelligence sources detected exploitation attempts starting on September 24, 2026, including efforts to deploy webshell backdoors. In response to these active attacks, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-65660 to its Known Exploited Vulnerabilities (KEV) catalog on September 25, 2026, mandating federal agencies to apply patches by September 28, 2026.

Severity: Critical

Threat Details and IOCs

CVEs: CVE-2026-65660
Technologies: Microsoft .NET, Microsoft SharePoint Server, Microsoft Windows Server
Attacker IPs: 169[.]150[.]248[.]21
Attacker URLs: /_layouts/15/AddGallery.aspx, /_layouts/15/designgallery.aspx, /_layouts/15/sphealth.aspx
Attacker Hashes: a151a8fc193a96aac480fa749547b57c0f33116cf2cb8c82b6aa716c3c47f4b1, d3faa4b443d98f272363f3484a5e6a9bab90979086aa2d31a1694c1dc8178742
Victim Industries: Construction, Education, Financial Services, Government, Healthcare, Legal Services, Manufacturing, Retail, Technology Hardware
Victim Countries: United States

Mitigation Advice

  • Apply the August 2026 security updates to all Microsoft SharePoint servers to remediate CVE-2026-65660.
  • Use a vulnerability scanner to immediately identify all Microsoft SharePoint servers in the environment that are vulnerable to CVE-2026-65660.
  • Hunt for newly created or recently modified files with extensions like .aspx, .ashx, or .asmx in SharePoint web application directories, as these could indicate the presence of a webshell.
  • Using your EDR or SIEM, search for suspicious child processes (e.g., cmd.exe, powershell.exe, certutil.exe) originating from the w3wp.exe process on all SharePoint servers.

Compliance Best Practices

  • Review and strengthen the organization's patch management policy to ensure critical vulnerabilities on internet-facing systems like SharePoint are remediated within 14 days of patch release.
  • Implement network micro-segmentation to restrict SharePoint servers to communicating only with necessary systems, such as domain controllers and SQL databases, on specific ports, and block all other lateral network traffic.
  • Implement a quarterly access review process for all accounts with permissions to SharePoint servers and enforce the principle of least privilege for both user and service accounts.
  • Deploy a Web Application Firewall (WAF) in front of all internet-facing SharePoint applications and enable rulesets that specifically screen for SharePoint attack patterns and generic code injection attempts.
  • Deploy a File Integrity Monitoring (FIM) solution on SharePoint servers to continuously monitor web directories for unauthorized file creation or modification and generate alerts for security team review.

CVE-2026-5430 in WSO2 and CVE-2026-71362 in Adobe Commerce Under Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical security vulnerabilities, CVE-2026-5430 and CVE-2026-71362, to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. CVE-2026-5430 is a path traversal vulnerability with a CVSS score of 9.8 affecting WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway, which allows unrestricted file uploads and subsequent remote code execution; active exploitation of this flaw has been observed in the wild since at least September 13, 2026. CVE-2026-71362 is an incorrect authorization vulnerability with a CVSS score of 9.1 affecting Adobe Commerce and Magento that enables attackers to hijack customer sessions and access private customer data without user interaction. Exploitation attempts targeting CVE-2026-71362 were blocked in August 2026, with further honeypot activity detected on September 10, 2026, originating from an IP address in Australia. Federal Civilian Executive Branch (FCEB) agencies are required to apply the necessary security patches for both vulnerabilities by September 27, 2026, to secure their networks against these active threats.

Severity: Critical

Threat Details and IOCs

Malware: CARBONATO, ChainDrop, GRIMWEDGE, KREMLIN, Mini Shai-Hulud, Sauron, Sauron Loader, Shai-Hulud
CVEs: CVE-2026-5430, CVE-2026-65660, CVE-2026-67279, CVE-2026-71362
Technologies: Adobe Commerce, Microsoft SharePoint Server, MikroTik RouterOS, WSO2 API Control Plane, WSO2 API Manager, WSO2 Traffic Manager, WSO2 Universal Gateway
Attacker Countries: Australia
Victim Industries: Banking, Business Services, Financial Services, Government, Healthcare, Logistics, Retail, Telecommunications, Transportation
Victim Countries: Netherlands, United States

Mitigation Advice

  • Apply the latest security patches to all instances of WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway to remediate CVE-2026-5430.
  • Apply the latest security patches to all instances of Adobe Commerce and Magento to remediate CVE-2026-71362.
  • Immediately run vulnerability scans and review asset inventories to identify all internet-facing and internal instances of WSO2 and Adobe Commerce/Magento products in our environment.
  • Review web server, application, and WAF logs for indicators of compromise, such as unusual file upload attempts or path traversal patterns targeting WSO2 systems, and anomalous customer session switching on Adobe Commerce platforms.

Compliance Best Practices

  • Establish a formal vulnerability management policy that incorporates CISA's KEV catalog as a primary source for prioritizing patching activities, ensuring that vulnerabilities under active exploitation are remediated first.
  • Deploy and configure a Web Application Firewall (WAF) in front of all public-facing WSO2 API gateways with rules designed to block path traversal and malicious file upload attacks.
  • Implement a Web Application Firewall (WAF) for the Adobe Commerce/Magento platform, with specific rules to monitor and block unauthorized or anomalous session manipulation and access control bypass attempts.
  • Implement and maintain a comprehensive software asset management program to ensure a continuously updated inventory of all applications and services, enabling rapid identification of systems affected by future vulnerabilities.

JADEPUFFER (Storm-3168) Conducts Destructive Cloud Attacks Targeting Microsoft Azure

In early June 2026, the threat actor Storm-3168, also known as JADEPUFFER, executed a highly automated, destructive cloud campaign targeting a compromised Azure tenant. The attack was facilitated by two compromised service principals whose credentials—including client ID, client secret, and tenant ID—had been previously exposed in plaintext within a public GitHub issue. The first service principal conducted extensive reconnaissance, performing over 300 successful read operations to enumerate virtual machines, subscriptions, and resource groups over a 15.5-hour period. Shortly after, a second service principal, utilizing the user-agent `python-requests/2.34.2` and operating from Storm-3168 infrastructure (including IP addresses `45.131.66.106`, `34.153.223.102`, and `64.20.53.230`), initiated a rapid seven-minute destructive sequence. This sequence involved over 100 storage account deletion attempts, the deletion of an Azure Key Vault, a Function App, and an App Service plan, alongside unsuccessful parallel attempts to delete Azure SQL databases using an unsupported API version. Following the destructive phase, the actor executed over 30 successful `ListKeys` requests to harvest storage account access keys, demonstrating tactics aligned with ransomware and extortion operations. Additionally, Storm-3168 infrastructure has been observed probing external targets for vulnerabilities in WordPress, PHP-CGI, and LangFlow's code validation endpoint (`/api/v1/validate/code`).

Severity: Critical

Threat Details and IOCs

Malware: ALPHV, BlackCat, Conti, encfile, EncForge, ENCFORGE, GOLD IONIC, Incransom, INC Ransom, INC Ransom (rebrand/successor), keyforge, lockd, Lynx, Noberus, Ryuk, WanaCrypt0r, WannaCry, WannaCryptor, Wanna Decryptor, WCry
CVEs: CVE-2021-29441, CVE-2025-3248, CVE-2025-55182, CVE-2025-66478, CVE-2026-24858
Technologies: Alibaba Nacos, Fortinet FortiGate, Fortinet SSL VPN, GitHub, Google TensorFlow, Langflow, Linux, Meta React Server Components, Microsoft Azure, MinIO, MySQL, PostgreSQL, Python, PyTorch, Vercel Next.js
Threat Actors: ALPHV, BlackCat, Conti, INC, Incransom, Jadepuffer, Lynx, Storm3168, TOXMAN
Attacker Countries: China, North Korea, Russia
Attacker IPs: 34[.]153[.]223[.]102, 45[.]131[.]66[.]106, 64[.]20[.]53[.]230
Attacker Emails: e78393397@proton[.]me, e78393397@proton[.]me, e78393397@proton[.]me
Attacker Domains: exploit[.]in, proton[.]me
Attacker URLs: /api/v1/validate/code, hxxp[:]//45.131.66.106:4444/beacon
Victim Industries: Cloud Infrastructure, Construction, Consumer Packaged Goods, Defense, Education, Financial Services, Government, Healthcare, Information Technology, Logistics, Manufacturing, Retail, Technology Hardware, Telecommunications
Victim Countries: Australia, Canada, China, France, Germany, Iraq, Japan, New Zealand, South Korea, Spain, Taiwan, Tonga, Turkey, United Kingdom, United States, Vietnam

Mitigation Advice

  • Add the IP addresses 45.131.66.106, 34.153.223.102, and 64.20.53.230 to your firewall, WAF, and Azure Network Security Group blocklists.
  • Query Azure Monitor logs, web server access logs, and network traffic logs for the user agent string "python-requests/2.34.2" to hunt for related malicious activity.
  • Immediately scan all public code repositories, including the full edit history of GitHub issues and pull requests, for any exposed service principal credentials, storage keys, or other secrets associated with your organization.
  • For any credentials found exposed in a public location, immediately revoke the credential and rotate it with a new one, then investigate its historical usage for signs of compromise.
  • Apply "CanNotDelete" resource locks in Azure on all critical production resources, especially storage accounts, databases, and backup vaults, to prevent malicious or accidental deletion.

Compliance Best Practices

  • Initiate a project to audit all Azure RBAC permissions assigned to service principals and other workload identities, enforcing the principle of least privilege by restricting them to only the specific resources and operations required for their function.
  • Establish and enforce a formal credential lifecycle management policy that mandates periodic rotation for all service principal secrets and other long-lived credentials.
  • Integrate automated secret scanning tools into your CI/CD pipeline to detect and block credentials from being committed to source code repositories.
  • Implement strict, dedicated access controls for all backup and recovery infrastructure and configure monitoring to generate high-priority alerts on any attempt to modify or remove backup data or protection controls.
  • Plan and deploy Microsoft Defender for Storage to gain threat detection for unusual access, data exfiltration, and other malicious activities targeting Azure Storage accounts.
  • Plan and deploy Microsoft Defender for Databases to protect Azure SQL and other supported database services from data exfiltration attempts and other attacks.
  • Plan and deploy Microsoft Defender for Key Vault to monitor for suspicious access patterns and other signs of compromise related to your secrets management infrastructure.
  • Develop and mandate a recurring security training program for all developers that focuses on best practices for secrets management and the specific risks of exposing credentials in code repositories and public forums.

Authors & Contributors

Brian Sayer (Author)

Threat Intelligence Analyst, F5