#NetScaler
All CosmicBytez Labs articles tagged #NetScaler, across news, security advisories, how-to guides, and projects.
- News
Mandiant: Suspected State Hackers Exploited NetScaler Zero-Day for Three-Plus Weeks Undetected
Mandiant traced NetScaler zero-day exploitation to Sept. 3, weeks before detection, hitting dozens of orgs tied to suspected state actors.
- News
Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers
Two critical NetScaler zero-days (CVSS 9.5) hit default Citrix configs; CISA lists both as exploited, with no workarounds available.
- News
Hackers Exploit Citrix NetScaler Zero-Day to Deploy Web Shells
Hackers exploited Citrix NetScaler zero-day CVE-2026-88772 to deploy WHIPSHOT web shells and SLAPSHOT tunneling malware, gaining root access pre-patch.
- News
US, UK, and Dutch Agencies Warn of Actively Exploited Citrix NetScaler Zero-Days
US, UK, and Dutch agencies warn Citrix NetScaler ADC and Gateway zero-days CVE-2026-88771 and CVE-2026-88772 are under active global exploitation.
- Newsletter
Weekly Digest — Issue #37
Dual Citrix NetScaler zero-days spark global chaos, Apple patches a Meta-reported spyware bug, and an agentic AI attacker wipes an Azure tenant in 7 minutes.
- News
Citrix Patches Actively Exploited NetScaler Zero-Days After a Weekend of Unofficial Warnings
Citrix stayed publicly silent for days while CERTs, insurers, and researchers warned of active NetScaler exploitation ahead of its own advisory.
- Security
CVE-2026-88773: Citrix NetScaler HTTP Request Smuggling Flaw
Citrix patches a CVSS 9.3 HTTP request smuggling flaw in NetScaler ADC/Gateway that can enable cache poisoning and auth bypass at the proxy layer.
- Security
CVE-2026-88775: Citrix NetScaler Memory Overflow Vulnerability
A critical memory overflow flaw in Citrix NetScaler ADC/Gateway (CVSS 9.8) risks crashes or worse on Gateway and AAA virtual servers — patch now.
- News
Citrix Confirms Two NetScaler RCE Zero-Days, Ships Patches as CVE-2026-88771 and CVE-2026-88772
Citrix confirmed and patched two exploited NetScaler RCE zero-days watchTowr warned about a day earlier — August's fixed builds remain vulnerable.
- News
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
watchTowr warns two unconfirmed Citrix NetScaler RCE zero-days are being exploited; Citrix has issued no CVE, patch, or advisory yet.
- News
CISA Orders Feds to Patch Actively Exploited Citrix Flaw by Thursday
CISA has issued a mandatory patching directive ordering all U.S. federal agencies to apply Citrix NetScaler security updates by Thursday, March 5, 2026,...
- News
Critical Citrix NetScaler Memory Flaw Actively Exploited in Attacks
Hackers are actively exploiting a critical memory overread vulnerability tracked as CVE-2026-3055 in Citrix NetScaler ADC and NetScaler Gateway appliances...
- News
Citrix NetScaler CVE-2026-3055 (CVSS 9.3) Under Active
Security researchers at Defused Cyber and watchTowr have detected active reconnaissance targeting CVE-2026-3055, a critical CVSS 9.3 memory overread flaw...
- News
Citrix Urges Admins to Patch NetScaler Flaws as Soon as
Citrix has patched two NetScaler ADC and Gateway vulnerabilities — including a critical CVSS 9.3 out-of-bounds read flaw eerily similar to the previously...