{"id":2101,"date":"2026-09-30T15:02:14","date_gmt":"2026-09-30T09:32:14","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=2101"},"modified":"2026-10-05T09:44:56","modified_gmt":"2026-10-05T04:14:56","slug":"citrix-netscaler-cve-2026-88772","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/","title":{"rendered":"Citrix NetScaler CVE-2026-88772 Exploitation: Web Shells, Root Access and Internal Tunneling"},"content":{"rendered":"<p>Citrix NetScaler CVE-2026-88772 has moved beyond a critical vulnerability disclosure into a documented post-exploitation campaign.<\/p>\n<p>Mandiant and Google Threat Intelligence Group (GTIG) identified active exploitation affecting NetScaler ADC and NetScaler Gateway appliances. Evidence suggests the campaign has operated since at least early September 2026.<\/p>\n<p>Affected organizations were located in North America and Europe. They spanned government, financial services, technology, education, legal and professional services.<\/p>\n<p>The attack chain is particularly significant because exploitation occurs before authentication and can provide root-level execution on the NetScaler appliance. In observed intrusions, attackers subsequently established persistence by modifying web server configurations, deploying web shells, and altering <code>\/bin\/sh<\/code> permissions. Mandiant also observed attackers using compromised appliances to proxy traffic into internal networks.<\/p>\n<p>CVE-2026-88772 is a critical memory-overflow vulnerability in NetScaler ADC and NetScaler Gateway that can cause remote code execution or denial of service when <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-datagram-tls-dtls\/\">DTLS<\/a> is enabled. Citrix assigned the vulnerability a CVSS v4.0 score of 9.5 and confirmed exploitation in the wild.<\/p>\n<h2>Citrix NetScaler CVE-2026-88772 at a Glance<\/h2>\n<table style=\"font-weight: 400; width: 98.3544%;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"12\" aria-colcount=\"2\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"width: 41.6332%; background-color: #e4e8eb; text-align: center;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Vulnerability Attribute<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.0616%; background-color: #e4e8eb; text-align: center;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Information<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td style=\"width: 41.6332%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">CVE<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.0616%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CVE-2026-88772<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td style=\"width: 41.6332%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Affected products<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.0616%;\" data-celllook=\"0\"><span data-contrast=\"auto\">NetScaler ADC and NetScaler Gateway<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td style=\"width: 41.6332%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Vulnerability type<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.0616%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Memory overflow \/ CWE-119<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td style=\"width: 41.6332%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">CVSS<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.0616%;\" data-celllook=\"0\"><span data-contrast=\"auto\">9.5, Critical, CVSS v4.0<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td style=\"width: 41.6332%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Attack prerequisite<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.0616%;\" data-celllook=\"0\"><span data-contrast=\"auto\">DTLS enabled; DTLS is enabled by default on VPN vServers<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td style=\"width: 41.6332%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Potential impact<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.0616%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Remote code execution or denial of service<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td style=\"width: 41.6332%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Observed execution context<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.0616%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Root-level access in documented exploitation<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td style=\"width: 41.6332%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Exploitation status<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.0616%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Confirmed active exploitation<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td style=\"width: 41.6332%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Fixed NetScaler ADC\/Gateway builds<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.0616%;\" data-celllook=\"0\"><span data-contrast=\"auto\">14.1-73.37 and 13.1-64.23 or later<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td style=\"width: 41.6332%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Fixed FIPS\/NDcPP builds<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.0616%;\" data-celllook=\"0\"><span data-contrast=\"auto\">14.1-73.37 FIPS and 13.1-37.279 FIPS\/NDcPP or later<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"12\">\n<td style=\"width: 41.6332%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">CISA KEV<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.0616%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Added September 27, 2026<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>CVE-2026-88772 requires DTLS to be enabled, according to Citrix. NetScaler Gateway VPN virtual servers enable DTLS by default unless administrators explicitly disable it.<\/p>\n<h2>How Malformed DTLS Traffic Reaches Root on NetScaler<\/h2>\n<p>The available evidence provides a clearer picture of how Citrix NetScaler CVE-2026-88772 reaches code execution.<\/p>\n<p>During the pre-authentication cryptographic handshake, the NetScaler Packet Processing Engine, or NSPPE, parses incoming DTLS record structures.<\/p>\n<p>GTIG does not possess the exploit code. However, its analysis of frontline telemetry suggests specially malformed or fragmented DTLS record headers can trigger heap memory boundary corruption inside NSPPE. The corruption can divert execution to attacker-supplied shellcode with root-level privileges on the underlying FreeBSD platform.<\/p>\n<p>Successful exploitation attempts also produced observable artifacts. These included DTLS handshake failures and messages showing unexpected NSPPE process termination.<\/p>\n<p>This distinction matters. Citrix describes the vulnerability broadly as a memory overflow leading to RCE or denial of service. <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=citrix_netscaler_cve_2026_88772\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">Mandiant and GTIG&#8217;s incident-response evidence<\/a> provides the more detailed explanation of how exploitation appears to work in observed environments.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/How-Endpoint-Isolation-Stops-Lateral-Movement-During-an-Active-Attack-1024x535-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>How Endpoint Isolation Stops Lateral Movement During an Active Attack<\/h4><p>Learn how endpoint isolation restricts network access during an active compromise.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/how-endpoint-isolation-stops-lateral-movement-during-an-active-attack\/\" aria-label=\"How Endpoint Isolation Stops Lateral Movement During an Active Attack\"><\/a><\/div><\/div><\/div>\n<h2>Attackers Turned Web Server Configuration Into Persistence<\/h2>\n<p>After gaining root-level execution, attackers established additional persistence on the appliance.<\/p>\n<p>Mandiant found attackers modifying NetScaler <code>httpd.conf<\/code> files so extensions that would not normally indicate PHP code could execute as PHP scripts.<\/p>\n<p>Observed examples included files masquerading as Debian packages, signature files and other web assets. Some web shells returned fake HTTP 404 Not Found responses while processing encoded attacker commands.<\/p>\n<p>The attackers also addressed a privilege problem created after initial exploitation.<\/p>\n<p>Initial exploitation executes with root privileges. However, subsequent requests handled by the web server run under an unprivileged service context. Mandiant observed attackers setting the setuid bit on <code>\/bin\/sh<\/code> using <code>chmod u+s \/bin\/sh<\/code>. This allowed subsequent web-shell commands to execute with elevated permissions.<\/p>\n<p>Attackers also restarted the web server or rebooted the NetScaler appliance to activate configuration changes. Organizations should investigate previously exposed appliances for persistence even after applying the security update.<\/p>\n<h2>WHIPSHOT and SLAPSHOT Turn NetScaler Into an Internal Proxy<\/h2>\n<p>Mandiant identified two previously undocumented malware families in the campaign: WHIPSHOT and SLAPSHOT.<\/p>\n<p>WHIPSHOT is a PHP web shell disguised as a Debian package. It accepts encoded data through HTTP request headers and acts as the external transport layer for SLAPSHOT.<\/p>\n<p>WHIPSHOT communicates locally with SLAPSHOT through the loopback interface. It can also launch the Python payload if the tunneler is not already running.<\/p>\n<p>SLAPSHOT provides the TCP tunneling layer used to reach internal hosts.<\/p>\n<p>The Python-based tunneler can establish arbitrary TCP connections to target hosts and relay traffic through the compromised NetScaler appliance. Its command protocol supports opening connections, transmitting data, receiving data and closing sessions.<\/p>\n<p>More importantly, this was not only a theoretical malware capability. In at least one observed intrusion, Mandiant saw the threat actor route traffic through the proxy to conduct internal reconnaissance and credential theft.<\/p>\n<p>That activity changes the incident-response boundary. Defenders should not limit investigation to the compromised NetScaler appliance when evidence indicates attackers may have used it as a path toward internal systems.<\/p>\n<h2>Patch CVE-2026-88772, Then Hunt for Existing Persistence<\/h2>\n<p>Citrix confirmed exploitation of both CVE-2026-88772 and CVE-2026-88771 on unmitigated NetScaler deployments. CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on September 27.<\/p>\n<p>For CVE-2026-88772, organizations should first determine whether DTLS is enabled. According to Citrix, the vulnerability affects NetScaler ADC or NetScaler Gateway when DTLS is enabled.\u00a0NetScaler Gateway VPN virtual servers enable DTLS by default unless administrators explicitly disable it.<\/p>\n<p>Citrix recommends installing the relevant fixed build:<\/p>\n<ul>\n<li>NetScaler ADC and Gateway 14.1-73.37 or later<\/li>\n<li>NetScaler ADC and Gateway 13.1-64.23 or later<\/li>\n<li>NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS or later<\/li>\n<li>NetScaler ADC 13.1-FIPS\/NDcPP 13.1-37.279 or later<\/li>\n<\/ul>\n<p>Mandiant likewise recommends prioritizing the latest Citrix build. However, organizations should investigate for compromise rather than treating patch installation as post-incident remediation by itself.<\/p>\n<p>Investigators should review the appliance for altered web server configuration, unexpected executable PHP handlers, suspicious web shells and unauthorized setuid permissions on <code>\/bin\/sh<\/code>. Mandiant also recommends extending hunting across broader infrastructure for potential activity originating from compromised NetScaler systems.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Thumbnail-For-XDR-Intro-Deck\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1.webp?format=webp 1796w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1-300x168.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1-1024x575.webp?format=webp 1024w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1-768x431.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1-1536x862.webp?format=webp 1536w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1-178x100.webp?format=webp 178w\" sizes=\"auto, (max-width: 1796px) 100vw, 1796px\" title=\"Thumbnail-For-XDR-Intro-Deck\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Introduction to Hexnode XDR\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            See how Hexnode XDR brings endpoint threat visibility, investigation, and response capabilities into a unified security workflow.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/introduction-to-hexnode-xdr\/'>\n                            Download the Presentation\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Investigating Downstream Endpoint Activity With Hexnode XDR<\/h2>\n<p>Hexnode XDR does not replace the Citrix security update or appliance-level investigation. It should also not be positioned as detecting CVE-2026-88772 exploitation on NetScaler.<\/p>\n<p>Its relevance begins downstream.<\/p>\n<p>Mandiant observed compromised NetScaler appliances being used to proxy traffic into internal networks. SLAPSHOT provided the TCP tunneling layer that allowed attackers to connect to internal hosts through the compromised appliance. In at least one intrusion, attackers used this proxy path for internal reconnaissance and credential theft.<\/p>\n<p>This activity gives security teams a reason to investigate managed endpoints reachable from the affected environment. <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> provides security visibility across supported Windows and macOS endpoints. Security teams can use endpoint telemetry and query-based Threat Hunt capabilities to investigate suspicious downstream activity.<\/p>\n<p>Where investigation identifies a compromised endpoint, the response actions include:<\/p>\n<ul>\n<li>Isolate Device to restrict endpoint network access.<\/li>\n<li>Kill Process to terminate an identified malicious process.<\/li>\n<li>Quarantine File to contain an identified threat file.<\/li>\n<li>Delete File to remove an identified malicious file.<\/li>\n<\/ul>\n<p>Security teams can separately use Threat Hunt and its query engine for broader endpoint investigation.<\/p>\n<p>These controls operate on managed endpoints. They do not inspect, clean, patch or remediate the NetScaler appliance itself.<\/p>\n<h2>What to Do After CVE-2026-88772 Exposure<\/h2>\n<p>Organizations running affected NetScaler deployments should prioritize four actions:<\/p>\n<ol>\n<li><strong>Identify affected NetScaler configurations.<\/strong> Determine whether deployed versions are vulnerable and whether DTLS is enabled for CVE-2026-88772 exposure.<\/li>\n<li><strong>Install Citrix&#8217;s fixed builds.<\/strong> Apply the appropriate 14.1, 13.1 or FIPS\/NDcPP update without unnecessary delay.<\/li>\n<li><strong>Hunt the appliance for post-exploitation artifacts.<\/strong> Review web server configuration, web shells, suspicious file handlers and <code>\/bin\/sh<\/code> permissions.<\/li>\n<li><strong>Expand investigation beyond NetScaler when compromise is suspected.<\/strong> Review internal systems for activity consistent with reconnaissance, credential access or subsequent attacker movement.<\/li>\n<\/ol>\n<p>The campaign shows that an edge-device compromise can extend beyond the affected appliance and expose internal systems to further attacker activity.<\/p>\n<h3>Conclusion<\/h3>\n<p>Citrix NetScaler CVE-2026-88772 gave attackers more than an opportunity to crash an exposed service.<\/p>\n<p>Mandiant documented a chain from pre-authentication DTLS processing to root-level execution, persistent PHP web shells and an internal tunneling architecture built around WHIPSHOT and SLAPSHOT. Attackers used that infrastructure for internal reconnaissance and credential theft in at least one observed intrusion.<\/p>\n<p>Updating affected NetScaler appliances addresses CVE-2026-88772, while suspected compromises require further investigation.<\/p>\n<p>For those downstream endpoints, endpoint investigation and containment can complement the appliance-focused response. They do not substitute for Citrix&#8217;s patches or NetScaler-specific forensic investigation.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Endpoint Investigation and Response<\/h5><p>Bring endpoint visibility, threat investigation, and response actions into a unified workflow with Hexnode XDR.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Citrix NetScaler CVE-2026-88772 has moved beyond a critical vulnerability disclosure into a documented post-exploitation campaign&#8230;.<\/p>\n","protected":false},"author":4,"featured_media":2125,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[12,20],"class_list":["post-2101","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zero-day","category-network-and-vpn","product_category-extended-detection-and-response","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Citrix NetScaler CVE-2026-88772 Exploited in Attacks<\/title>\n<meta name=\"description\" content=\"Citrix NetScaler CVE-2026-88772 attacks deployed web shells, gained root access and tunneled into internal networks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Citrix NetScaler CVE-2026-88772 Exploited in Attacks\" \/>\n<meta property=\"og:description\" content=\"Citrix NetScaler CVE-2026-88772 attacks deployed web shells, gained root access and tunneled into internal networks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-30T09:32:14+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-05T04:14:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Citrix-NetScaler-CVE-2026-88772-Exploitation-Web-Shells-Root-Access-and-Internal-Tunneling.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/citrix-netscaler-cve-2026-88772\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/citrix-netscaler-cve-2026-88772\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"Citrix NetScaler CVE-2026-88772 Exploitation: Web Shells, Root Access and Internal Tunneling\",\"datePublished\":\"2026-09-30T09:32:14+00:00\",\"dateModified\":\"2026-10-05T04:14:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/citrix-netscaler-cve-2026-88772\\\/\"},\"wordCount\":1331,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/citrix-netscaler-cve-2026-88772\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Citrix-NetScaler-CVE-2026-88772-Exploitation-Web-Shells-Root-Access-and-Internal-Tunneling.jpeg?format=webp\",\"articleSection\":[\"Zero-Day\",\"Network and VPN\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/citrix-netscaler-cve-2026-88772\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/citrix-netscaler-cve-2026-88772\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/citrix-netscaler-cve-2026-88772\\\/\",\"name\":\"Citrix NetScaler CVE-2026-88772 Exploited in Attacks\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/citrix-netscaler-cve-2026-88772\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/citrix-netscaler-cve-2026-88772\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Citrix-NetScaler-CVE-2026-88772-Exploitation-Web-Shells-Root-Access-and-Internal-Tunneling.jpeg?format=webp\",\"datePublished\":\"2026-09-30T09:32:14+00:00\",\"dateModified\":\"2026-10-05T04:14:56+00:00\",\"description\":\"Citrix NetScaler CVE-2026-88772 attacks deployed web shells, gained root access and tunneled into internal networks.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/citrix-netscaler-cve-2026-88772\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/citrix-netscaler-cve-2026-88772\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/citrix-netscaler-cve-2026-88772\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Citrix-NetScaler-CVE-2026-88772-Exploitation-Web-Shells-Root-Access-and-Internal-Tunneling.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Citrix-NetScaler-CVE-2026-88772-Exploitation-Web-Shells-Root-Access-and-Internal-Tunneling.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"Citrix NetScaler CVE-2026-88772 Exploitation Web Shells Root Access and Internal Tunneling\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/citrix-netscaler-cve-2026-88772\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Citrix NetScaler CVE-2026-88772 Exploitation: Web Shells, Root Access and Internal Tunneling\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"description\":\"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Citrix NetScaler CVE-2026-88772 Exploited in Attacks","description":"Citrix NetScaler CVE-2026-88772 attacks deployed web shells, gained root access and tunneled into internal networks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/","og_locale":"en_US","og_type":"article","og_title":"Citrix NetScaler CVE-2026-88772 Exploited in Attacks","og_description":"Citrix NetScaler CVE-2026-88772 attacks deployed web shells, gained root access and tunneled into internal networks.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-30T09:32:14+00:00","article_modified_time":"2026-10-05T04:14:56+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Citrix-NetScaler-CVE-2026-88772-Exploitation-Web-Shells-Root-Access-and-Internal-Tunneling.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"Citrix NetScaler CVE-2026-88772 Exploitation: Web Shells, Root Access and Internal Tunneling","datePublished":"2026-09-30T09:32:14+00:00","dateModified":"2026-10-05T04:14:56+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/"},"wordCount":1331,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Citrix-NetScaler-CVE-2026-88772-Exploitation-Web-Shells-Root-Access-and-Internal-Tunneling.jpeg?format=webp","articleSection":["Zero-Day","Network and VPN"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/","url":"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/","name":"Citrix NetScaler CVE-2026-88772 Exploited in Attacks","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Citrix-NetScaler-CVE-2026-88772-Exploitation-Web-Shells-Root-Access-and-Internal-Tunneling.jpeg?format=webp","datePublished":"2026-09-30T09:32:14+00:00","dateModified":"2026-10-05T04:14:56+00:00","description":"Citrix NetScaler CVE-2026-88772 attacks deployed web shells, gained root access and tunneled into internal networks.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Citrix-NetScaler-CVE-2026-88772-Exploitation-Web-Shells-Root-Access-and-Internal-Tunneling.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Citrix-NetScaler-CVE-2026-88772-Exploitation-Web-Shells-Root-Access-and-Internal-Tunneling.jpeg?format=webp","width":1340,"height":754,"caption":"Citrix NetScaler CVE-2026-88772 Exploitation Web Shells Root Access and Internal Tunneling"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/citrix-netscaler-cve-2026-88772\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Citrix NetScaler CVE-2026-88772 Exploitation: Web Shells, Root Access and Internal Tunneling"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"description":"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2101","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=2101"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2101\/revisions"}],"predecessor-version":[{"id":2127,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2101\/revisions\/2127"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/2125"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=2101"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=2101"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}