Citrix shipped fixes for two NetScaler ADC and Gateway zero-days on September 27: CVE-2026-88771, an improper input validation flaw rated CVSS 9.5 that hits every deployment in its default configuration, and CVE-2026-88772, which bypasses authentication outright by forcing an unhandled termination of the NetScaler Packet Processing Engine. The next day, CISA, the UK, and the Netherlands issued a joint advisory confirming what Mandiant and Google’s Threat Intelligence Group had already found: both bugs had been under active exploitation since early September, roughly three to four weeks before anyone outside the attack had a name for them.
That timeline is the story, not the CVSS scores. By the time a NetScaler admin applied Tuesday’s patch, the attacker who found these bugs first had already had a month of unauthenticated root access to plant whatever they wanted. On Wednesday, LevelBlue’s threat hunting team confirmed exactly what that looked like in practice: post-exploitation payloads that create a superuser account and map a web shell to a URL path styled to look like a CSS stylesheet request, the kind of thing a log reviewer scans past without a second look. Patching the vulnerability does nothing about the superuser account or the disguised web shell already sitting on the box. For every organization that ran an affected NetScaler appliance in September, “we patched” and “we are secure” are now two different claims, and only one of them is true without a compromise hunt to back it up.
What a month of silent access actually buys an attacker
The tooling identified alongside the exploitation tells you what that month was for. Mandiant and GTIG documented a custom PHP web shell called Whipshot that tunnels command-and-control traffic inside native HTTP headers rather than a request body or a distinguishable parameter, which is specifically built to survive the kind of network monitoring that inspects payloads but not header fields. Alongside it, a Python tool called Slapshot handled reconnaissance and credential theft once the shell was in place. This isn’t smash-and-grab tooling. Header-based C2 concealment and a dedicated credential harvester are built for an operator who expects to stay resident and wants the access to survive a cursory incident response pass.
The victim list backs that up: government, financial services, technology, education, and legal and professional services across North America and Europe, confirmed by Mandiant Consulting directly, not inferred from scanning telemetry. That’s a targeting profile that favors data and access value over volume, which lines up with a month-long dwell window spent on reconnaissance and credential theft rather than immediate ransomware deployment. Whoever had this exploit chain first treated it like an investment, not a smash-and-grab, and the September 26 disclosure (a day after researcher watchTowr published its own analysis of the NetScaler flaws, which appears to have forced Citrix’s hand on timing) cut that investment period short only because outside researchers found the bugs independently.
This is the fourth consecutive month this pipeline has tracked a pre-auth, unauthenticated zero-day landing on network-edge infrastructure: Ivanti, Fortinet, and Check Point/Arista/F5 earlier in September, now Citrix. The pattern holds because the economics haven’t changed. NetScaler appliances sit on the internet-facing perimeter by design, run closed-source firmware that resists the kind of EDR instrumentation that would catch a superuser account being created, and get patched on a change-control cycle owned by network teams, not a security team’s emergency response clock. An exploit broker shopping a bug against that deployment model isn’t selling a vulnerability, they’re selling a month of quiet root access to a target population that structurally cannot detect it fast. Citrix is not a uniquely insecure vendor. It is this month’s instance of a category attackers have decided is worth more than the equivalent endpoint bug.
The defender blind spot is specific and fixable: organizations treating “patch applied” as the closing step of an incident rather than its opening one. Any NetScaler ADC or Gateway appliance that was internet-facing and unpatched between early September and September 27 needs to be treated as a confirmed-compromise assumption, not a patched-and-clear one. That means checking for unauthorized superuser accounts, auditing for web shells mapped to static-asset-style URL paths, and reviewing outbound HTTP header traffic for anomalies, not just confirming the firmware version.
Escalation from last week: the ShinyHunters PeopleSoft claim gets a mechanism
Last week’s brief treated ShinyHunters’ claimed breach of the FBI’s jobs portal as unconfirmed: a 2-to-3-terabyte data theft claim tied to an unnamed PeopleSoft flaw, with no CVE, no KEV entry, and no patch to point to. That gap closed partially this week. The vulnerability has a name: CVE-2026-35273, a CVSS 9.8 PeopleSoft PSEMHUB deserialization flaw that ShinyHunters (tracked by Mandiant as UNC6240) first used as a genuine zero-day back in May and June against the education sector. What’s new is the delivery mechanism: the group is now URL-encoding a single character in the request path to slip past web application firewall rules that organizations deployed as a stopgap instead of patching. WAF-only mitigation against a known, previously-exploited bug just failed in the field, and the renewed campaign has placed web shells across higher education, technology, healthcare, agriculture, transportation, and government. The FBI has confirmed it is investigating the FBIJobs.gov claim specifically but still has not verified the data volume or scope ShinyHunters is asserting. The claim went from unconfirmed to partially mechanistically confirmed; the headline number did not.
What to watch
Two threads carry past this brief. First, whether the NetScaler compromises produce confirmed downstream breaches or ransomware deployments once the month-long reconnaissance window the attackers had translates into action. Previous network-edge KEV entries this year have reliably converted into later ransomware initial-access reporting, and there is no reason to expect NetScaler to be the exception. Second, whether Oracle issues anything beyond a patch note for PeopleSoft, given that this is now the second confirmed exploitation wave against the same CVE in four months and WAF mitigation has publicly failed against it.
Security Unlocked publishes threat intelligence and strategic analysis twice weekly. This mid-week brief covers developments from September 28, 2026 through October 1, 2026.
Security