Attackers are exploiting CVE-2026-88771, a critical pre-authentication command-injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway, to deploy reverse shells, create privileged accounts, and establish persistent access. LevelBlue’s Threat Hunt Operations & Research (THOR) team identified malicious authentication events across multiple customer environments, documenting activity extending beyond vulnerability testing into payload execution and configuration theft […]
Read the original article:
