Citrix NetScaler zero-days actively exploited since September


CVE-2026-88772 and CVE-2026-88771 have been exploited in the wild since early September, targeting Citrix NetScaler ADC and Gateway appliances. Mandiant confirmed attacks against government, financial, technology, and legal sectors across North America and Europe. The DTLS handshake vulnerability enables root-level code execution via malformed UDP:443 packets. Post-exploitation deploys WHIPSHOT web shells and SLAPSHOT tunnelers for lateral movement. Citrix released patches in NetScaler 14.1-73.37+ and 13.1-64.23+.

Elsewhere, Cloudflare applied to four root programs and is acquiring GlobalSign's root to become a public CA. First Merkle Tree Certificate issuance targets Q1 2027 for post-quantum authentication.

In this issue:

  • Citrix NetScaler CVE-2026-88772/88771: active exploitation, patching urgency
  • Cloudflare entering public CA space with GlobalSign root acquisition
  • Google Cloud Z4D: 84TB local SSD, 15.6M IOPS, AMD EPYC Turin
  • Arch Linux Archinstall 4.5: AArch64 bootloader and real-time kernel support

Citrix NetScaler Zero-Days Under Active Exploitation

The Signal

CVE-2026-88772 and CVE-2026-88771 affecting Citrix NetScaler ADC and Gateway appliances have been actively exploited since early September.

What Changed

  • Mandiant and Google Threat Intelligence Group confirmed in-the-wild exploitation targeting government, financial, technology, education, and legal sectors in North America and Europe.
  • CVE-2026-88772 exploits DTLS handshake parsing in NSPPE via malformed UDP:443 packets, triggering heap corruption and root-level code execution on FreeBSD.
  • Post-exploitation deploys WHIPSHOT, a PHP web shell disguising Base64 C2 in HTTP headers (`HTTP_X_UX`, `HTTP_NSC_LDAP`), and SLAPSHOT, a Python TCP tunneler proxying internal network traffic.
  • Persistence achieved by modifying `/etc/httpd.conf` to treat `.deb` or `.sig` files as PHP scripts and setting SUID bit on `/bin/sh` for root access.
  • Citrix released patches: NetScaler 14.1-73.37+ and 13.1-64.23+ address both vulnerabilities. https://docs.netscaler.com/en-us/netscaler-console-service/instance-advisory/security-advisory-dashboard.html

Operational Impact

Teams running NetScaler ADC or Gateway appliances exposed to the internet must patch immediately or apply compensating controls. Exploitation leaves minimal network telemetry—successful attacks generate `SSL_HANDSHAKE_FAILURE` logs with `DTLSv1.0` and `Handshake failure-Internal Error`, followed by NSPPE process terminations in `/var/log/messages`. Organizations unable to patch immediately should block inbound UDP:443 upstream, disable DTLS where not required, and audit `/etc/httpd.conf` for unauthorized `AddHandler` directives mapping non-PHP extensions to PHP execution. Assume credential exposure on compromised appliances—rotate administrator passwords, LDAP bind accounts, RADIUS secrets, TLS certificates, and terminate active Gateway sessions after patching. Review downstream Citrix infrastructure (StoreFront, Delivery Controllers) and PAM systems for lateral movement, particularly anomalous RDP sessions or credential dumping attempts.

Watch For

Monitor for `.sig` or `.deb` files in `/var/netscaler/gui/vpn/scripts/linux/` and HTTP 404 responses with multi-kilobyte bodies targeting `/vpn/media/*.ico` paths. The presence of `/tmp/.uxdport` or `/tmp/.uxdlock` indicates active SLAPSHOT tunneler deployment. Mandiant expects continued edge device targeting given this tactic's proven effectiveness—edge appliances remain outside EDR reach and often hold credentials enabling deeper network access.


Cloudflare Becoming a Public Certificate Authority

The Signal

Cloudflare applied to four root programs and is acquiring GlobalSign's root to issue public TLS certificates.

What Changed

  • Submitted applications to Chrome, Apple, Microsoft, and Mozilla root programs for new CA root
  • Signed agreement to acquire established GlobalSign root, trusted across devices since 2012
  • Plans first production Merkle Tree Certificate (MTC) issuance in Q1 2027 for post-quantum authentication
  • Will require ACME Renewal Information (RFC 9773) support as condition of issuance: https://blog.cloudflare.com/cloudflare-certificate-authority
  • Free ACME-first model targets redundancy for Let's Encrypt (~10M daily certificates, 500M+ sites)

Operational Impact

This adds a second large-scale free CA to the web PKI. Teams already using ACME clients can switch by updating directory URLs with no tooling changes. The acquired GlobalSign root provides immediate broad client compatibility while new roots target future policies and post-quantum requirements. Mandatory ARI support means issuance requires automation that polls renewal endpoints and tracks certificate replacement.

Watch For

Root program approval timelines are public but unpredictable. First MTC issuance in early 2027 will test Chrome's quantum-resistant certificate path at production scale.


Google Cloud Z4D: 84TB Local SSD Storage Instances

The Signal

Google Cloud's Z4D VMs deliver up to 84TB local SSD with 5th Gen AMD EPYC Turin.

What Changed

  • Two variants: z4d-highmem-standardlssd (219 GiB/vCPU) and z4d-highmem-highlssd (438 GiB/vCPU).
  • Performance: 15.6M random read IOPS, 75.6 GiB/s sequential read via Titanium SSDs.
  • Gains over Z3: 40% faster compute, 70% faster LSSD, 25% lower write latency.
  • Supports up to 384 vCPUs, 3TB memory, 400 Gbps networking per instance.
  • Bare metal instances available for custom hypervisors and Nutanix Cloud Clusters. https://cloud.google.com/blog/products/compute/storage-optimized-z4d-vm-and-bare-metal-instances

Operational Impact

Z4D targets MySQL, Postgres, distributed databases, OLAP, and streaming pipelines that need high IOPS and storage density per node. VMs with 42TB LSSD or less support live migration during maintenance. Instances above 42TB require planned restarts with data preserved, so teams running max-capacity configurations must schedule maintenance windows instead of relying on transparent migration.

Watch For

Bare metal instances are in preview—contact Google Cloud sales for regional availability and access.


Arch Linux Archinstall 4.5: AArch64 and Real-Time Kernel Support

The Signal

Archinstall 4.5 adds AArch64 bootloader support and real-time kernel options to Arch's text-based installer.

What Changed

  • GRUB and Limine EFI installation now supports AArch64 architecture. https://github.com/archlinux/archinstall/pull/4641
  • Installer handles AArch64 root partition type GUID correctly for ARM64 systems. https://github.com/archlinux/archinstall/pull/4671
  • linux-rt and linux-rt-lts real-time kernels available during install. https://github.com/archlinux/archinstall/pull/4711
  • Hyprland, Labwc, Niri, Sway now use systemd-logind instead of polkit.
  • WiFi SSIDs with spaces now appear in network scan list. https://github.com/archlinux/archinstall/pull/4634

Operational Impact

Teams deploying Arch on ARM servers (Ampere Altra, AWS Graviton, Azure Cobalt) can now use Archinstall for automated provisioning. Previously, AArch64 deployments required manual bootloader configuration. RT kernel selection during install eliminates post-install kernel swaps for latency-sensitive workloads like audio processing or industrial control systems.

Watch For

The October Arch Linux ISO will ship with this installer version. ARM server deployments may still need manual firmware handling depending on vendor.


Quick Reads

  • Citrix NetScaler — Two zero-days exploited since September targeting government and financial sectors globally.
  • Cloudflare — Applying to become public CA, acquiring GlobalSign root for post-quantum certificates.
  • Google Cloud Z4D — New VMs offer 84TB local SSD with 15.6M IOPS performance.
  • Arch Linux — Archinstall 4.5 adds AArch64 bootloader and real-time kernel support options.

Subscribe to Signal Field

Data & infrastructure news. Subscribers get new posts by email a day before they go live on the site.

Email signup is coming soon — in the meantime, follow the Signal Field RSS feed.

Need a Custom MCP System?

Configuration & integration for your stack — from tool selection to production deployment. The directory recommends. The consultancy configures.

Get Started →