Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
4 intel reports
Cluster c05d5254 utilizes the PoisonedRefresh rootkit to inject fileless PHP web shells into F5 BIG-IP APM memory via CVE-2025-53521 exploitation.
UNC6508, a PRC-nexus threat actor, targets medical and military research institutions using INFINITERED malware to harvest credentials and exfiltrate data via manipulated compliance rules.
DirtyFrag is a sophisticated Linux kernel Local Privilege Escalation toolkit that uses page cache corruption and RxRPC/AF_ALG abuse to gain root access.
Unknown threat actors are exploiting CVE-2026-5426 in KnowledgeDeliver LMS using hardcoded machine keys to achieve RCE and deploy BLUEBEAM web shells and Cobalt Strike.