Connects to any signal across any vendor stack and powers adaptive AI Operatives that expose, detect, and neutralize cyberattacks.
Atlas Operations CenterSee what our SOC sees, review investigations, and see how we are protecting your business.
Technology IntegrationsAtlas connects to any signal across your current security tools. Whatever you're running, we're running with you.
Extend your team with immediate expertise, hands-on remediation, and the human accountability layer that boards, regulators, and cyber insurers require.
Threat Response UnitProactive threat intelligence, original threat research and a world-class team of seasoned industry veterans.
Response and RemediationPairs machine-speed containment with human judgment, delivering full threat response that's policy-bounded, reversible, and explainable.
MDR that moves first, multi-signal attack surface coverage, and 24/7 Elite threat hunters working as one continuous security program across any vendor stack.
Get unlimited Incident Response with threat suppression guarantee- anytime, anywhere.
Atlas Preempt deploys AI Operatives to continuously validate attack paths exposing attacker targets of opportunity before they take advantage.
Protect insurance operations from cyber attacks.
ConstructionSecure project data and jobsite operations.
FinanceDefend financial services from cyber disruption.
LegalSafeguard client data and legal operations.
ManufacturingStop threats before they disrupt production.
Private EquityProtect portfolio companies from cyber risk.
HealthcareDefend patient data and clinical operations.
RetailProtect customer data and retail operations.
Food SupplySecure the food supply chain from cyber threats.
Government and EducationProtect public sector and education systems.
Automotive DealershipsSecure dealership operations and customer data.
Stop ransomware before it spreads.
Identity ResponseStop identity-based cyberattacks.
Zero Day AttacksDetect and respond to zero-day exploits.
Cybersecurity ComplianceMeet regulatory compliance mandates.
Third-Party RiskDefend third-party and supply chain risk.
Cloud MisconfigurationEnd misconfigurations and policy violations.
Cyber RiskAdopt a risk-based security approach.
Mid-Market SecurityMid-market security essentials to prioritize.
Sensitive Data SecurityProtect your most sensitive data.
Cyber InsuranceMeet insurability requirements with MDR.
Cyber Threat IntelligenceOperationalize cyber threat intelligence.
Security LeadershipBuild a proven security program.
As of September 29th, 2026, eSentire has observed in-the-wild exploitation of CVE-2026-88771 and CVE-2026-88772, with identified attacks being traced back to early-September. CVE-2026-88771…
On September 27th, 2026, Citrix disclosed eight vulnerabilities impacting its Citrix NetScaler ADC and NetScaler Gateway products; two of which are zero-days. The first zero-day…
eSentire is a leader in Controlled Autonomy SecOps, protecting 2,000+ organizations across 35+ industries around the world. Founded in 2001, the company’s Controlled Autonomy SecOps operating model pairs agentic AI operatives with engineered human-judgment controls, delivering expert-depth security outcomes at machine speed without ceding accountability to opaque automation.
About Us Leadership Careers Event Calendar → Newsroom → Aston Villa Football Club →We provide sophisticated cybersecurity solutions for Managed Security Service Providers (MSSPs), Managed Service Providers (MSPs), and Value-Added Resellers (VARs). Find out why you should partner with eSentire, the Authority in Managed Detection and Response, today.
Search our site
Multi-Signal MDR with 300+ technology integrations to support your existing investments.
24/7 SOC-as-a-Service with unlimited threat hunting and incident handling.
We offer three flexible MDR pricing packages that can be customized to your unique needs.
The latest security advisories, blogs, reports, industry publications and webinars published by TRU.
Compare eSentire to other Managed Detection and Response vendors to see how we stack up against the competition.
See why 2000+ organizations globally have chosen eSentire for their MDR Solution.
As of September 29th, 2026, eSentire has observed in-the-wild exploitation of CVE-2026-88771 and CVE-2026-88772, with identified attacks being traced back to early-September. CVE-2026-88771 (CVSS: 9.8) and CVE-2026-88772 (CVSS: 8.1) are critical vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway that can lead to unauthenticated Remote Code Execution (RCE). eSentire published an initial advisory for these vulnerabilities on September 28th. Both vulnerabilities were disclosed by Citrix on September 27th, who confirmed that exploitation had been previously identified. Reporting from CERT-EU and Google also highlight observed attacks, resulting in the deployment of webshells.
As exploitation is ongoing, organizations should ensure that relevant patches are applied immediately. Any internet-facing NetScaler appliance that was unpatched in early September 2026 should be treated as compromised until an integrity assessment confirms they were not affected.
In September 2026, eSentire's Threat Response Unit (TRU) observed a threat actor exploiting CVE-2026-88771 against Internet-facing Citrix NetScaler Gateway appliances as early as September 5th, more than three weeks before the vulnerability was publicly disclosed. In one instance, the actor employed a two-stage technique that abuses the appliance's own logging. The actor sent a rapid series of web requests for a fictitious icon file (/vpn/media/<name>.ico), each with base64-encoded PHP code appended to the User-Agent string, causing the appliance's web server to record the code in its access log. At the same time, the actor submitted crafted values in the Gateway login username field that imitates a NetScaler Packet Engine heartbeat message, followed by operating system commands. A built-in log-processing script passes these commands to a shell, directing the appliance to extract the staged code from its logs, decode it and execute it with PHP. Exploitation does not depend on the login succeeding.
The decoded payload is a PHP webshell designed for stealth and persistence. TRU has identified at least two variants of this webshell. The first, referred to here as the .ico variant, is publicly available on VirusTotal. The second, referred to here as the .deb variant, has not been observed by TRU in public malware repositories. It contains the same command-handling code as the .ico variant but executes through files with a .deb extension, allowing it to blend in with the legitimate VPN client installation packages stored in the same directory. When first executed, each variant:
Once active, the webshell executes base64-encoded PHP code supplied in the NSC_CLIENTTYPE HTTP request header, a name chosen to resemble legitimate NetScaler traffic. It always returns an HTTP 404 "Not Found" response, so attacker traffic appears to be routine requests for missing files. In the .ico variant intrusion examined by TRU, the actor staged the payload and then polled the webshell path hourly, and later every ten minutes, for nearly two days. The webshell installation does not appear to have been completed in that intrusion. In a separate intrusion involving the .deb variant, TRU confirmed that the webshell was installed and actively operated from September 5th, with webshell responses indicative of data exfiltration. The actor subsequently used access obtained through the compromised Gateway to open sessions on internal virtual desktops and connect back to the NetScaler appliance over SSH, confirming lateral movement into the internal network. The same technique and payload were also associated with webshell deployment and data theft at other organizations during the same period.
The observed attacks closely match findings by CERT-EU, who highlight attacks leveraging HTTP requests with base64-encoded user agents, which were executed to deploy webshells following exploitation of CVE-2026-88771. Google highlighted attacks targeting CVE-2026-88772, which resulted in the deployment of the WHIPSHOT webshell and SLAPSHOT TCP tunneling tool. No attribution for the attacks were provided by CERT-EU or Google within their reports, but security researcher Kevin Beaumont suggests that the attacks may have been espionage-motivated. Following the disclosure of both flaws, various technical reports and unverified Proof-of-Concept (PoC) exploit code have been published, opening the door for threat actors of all skill levels and motivations to operationalize the exploits within attacks.
Organizations that operated Internet-facing, unpatched NetScaler appliances in early September 2026 should treat those appliances as potentially compromised until an integrity assessment demonstrates otherwise.
Fixed Versions:
Webshell Indicators:
References:
[1] https://nvd.nist.gov/vuln/detail/cve-2026-88771
[2] https://nvd.nist.gov/vuln/detail/cve-2026-88772
[3] https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
[4] https://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771
[5] https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances
[6] https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/
[7] https://cyberplace.social/@GossiTheDog/117351107654208046