
NetScaler CVE-2026-88772 Exploitation Deploys Root Malware
Attackers are actively exploiting a critical Citrix NetScaler zero-day, CVE-2026-88772, to gain root access and deploy custom WHIPSHOT and SLAPSHOT malware.
Every Cybersecurity story tagged Actively exploited CVEs.

Attackers are actively exploiting a critical Citrix NetScaler zero-day, CVE-2026-88772, to gain root access and deploy custom WHIPSHOT and SLAPSHOT malware.

Two critical Citrix NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being actively exploited in zero-day attacks to deploy webshells.

The U.S. Cybersecurity agency CISA has mandated patching for three actively exploited Linux kernel vulnerabilities.

Zhuque Lab at Tencent has released AI-Infra-Guard, an open-source scanner that checks AI infrastructure services against known CVEs.

Adobe has released patches for over 170 security flaws, including an urgent fix for a critical, actively exploited zero-day in Adobe Commerce and Magento.

A critical vulnerability in the Elementor Pro WordPress plugin is being exploited to upload malicious PHP files, allowing attackers to compromise websites.

September 2026's Patch Tuesday follows a record-breaking August with 398 CVEs patched. Experts highlight actively exploited SharePoint and Exchange flaws, while Microsoft works on a fix for the 'ShieldBreak' Defender vulnerability.