Interestana
Home/News/Attackers Exploit NetScaler Flaw for Root Access
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Attackers Exploit NetScaler Flaw for Root Access

Attackers Exploit NetScaler Flaw for Root Access

Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. This exploitation activity, identified by Mandiant Consulting and the Google Threat Intelligence Group (GTIG) in September 2026, has specifically targeted entities within the government, financial services, technology, education, and legal and professional sectors. The attackers are leveraging the vulnerability to achieve root access on compromised appliances, enabling them to deploy sophisticated malware.

Mandiant's analysis revealed that the threat actors are utilizing two distinct malware families, identified as WHIPSHOT and SLAPSHOT, following their initial compromise of the NetScaler devices. WHIPSHOT is described as a backdoor that allows attackers to execute arbitrary commands on the victim's system, providing persistent access and enabling further malicious actions. SLAPSHOT, on the other hand, is a tool designed for credential harvesting, allowing the attackers to steal sensitive login information from users and administrators. The combination of these tools suggests a multi-stage attack designed to gain deep access and exfiltrate valuable data.

The specific vulnerability being exploited is tracked as CVE-2023-3519, a critical remote code execution (RCE) flaw that affects NetScaler ADC and NetScaler Gateway. This flaw allows unauthenticated attackers to execute arbitrary code on the appliance with root privileges. Citrix released security advisories and patches for this vulnerability in July 2023, urging customers to update their systems immediately. The ongoing exploitation observed in September 2026 indicates that a significant number of organizations have not yet applied the necessary security updates, leaving them vulnerable to these advanced persistent threats. The broad impact across multiple critical sectors highlights the pervasive risk posed by unpatched network infrastructure.

The observed attacks demonstrate a sophisticated understanding of the NetScaler attack surface and a rapid adaptation to exploit newly disclosed vulnerabilities. The targeting of government and financial institutions suggests a motive for espionage, financial gain, or disruption of critical services. Mandiant and GTIG are continuing to monitor this activity and are providing recommendations for organizations to secure their NetScaler deployments. These recommendations include applying all relevant security patches, reviewing system logs for signs of compromise, and implementing robust network segmentation to limit the potential impact of any successful intrusion. The continued exploitation of this flaw underscores the persistent challenge of supply chain security and the critical need for timely patch management across all IT infrastructure.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next