Back to Blog
CVE-2026-33017, CVE-2026-21858, CVE-2025-68613, CVE-2026-3055: Citrix NetScaler — Manual Exploitation Enables Session Hijack (August 2026)
vulnerabilities

CVE-2026-33017, CVE-2026-21858, CVE-2025-68613, CVE-2026-3055: Citrix NetScaler — Manual Exploitation Enables Session Hijack (August 2026)

breachwire TeamSep 14, 20262 min read

CVE-2026-33017, CVE-2026-21858, CVE-2025-68613, CVE-2026-3055 — Citrix NetScaler

These high-severity CVEs affect Citrix NetScaler appliances and have been actively exploited in the wild. Attackers can extract authentication cookies from device memory, enabling full session hijack and unauthorized access to sensitive resources. No CVSS scores are published, but exploitation has resulted in real-world breaches.

Attack Vector

A Chinese threat actor known as knaithe leveraged both autonomous AI-driven reconnaissance (using large language models like DeepSeek) and manual exploitation. While AI-automated attacks failed to compromise over 647,000 exposed n8n workflow automation servers, manual exploitation targeted Citrix NetScaler appliances directly. Attackers used public exploits and targeted internet-facing systems, extracting authentication cookies from device memory on three successful breaches. This enabled hijacking of active user sessions and access to protected data.

Who Is at Risk

Citrix NetScaler appliances with internet exposure are at immediate risk, especially those running unpatched versions vulnerable to CVE-2026-33017, CVE-2026-21858, CVE-2025-68613, and CVE-2026-3055. Over 460 systems were targeted, with three confirmed breaches. Organizations in the Asia-Pacific region are specifically impacted, but global exposure is likely.

Patch & Mitigate

  • Patch: Apply the latest Citrix NetScaler security updates addressing these CVEs immediately. Check vendor advisories for hotfixes and deadlines.
  • Workaround: Restrict internet exposure of management interfaces; enforce network segmentation.
  • Detect: Review logs for anomalous session activity, unexpected authentication cookie access, and connections from suspicious IPs. Monitor for signs of session hijack or memory scraping.

MITRE ATT&CK

  • T1078 — Valid Accounts: Attackers leveraged stolen authentication cookies to hijack legitimate sessions.
  • T1003 — OS Credential Dumping: Extraction of authentication data from device memory aligns with credential dumping techniques.
  • T1190 — Exploit Public-Facing Application: Initial access was gained via exploitation of internet-facing Citrix NetScaler appliances.

Source: https://www.helpnetsecurity.com/2026/08/03/deepseek-ai-autonomous-cyberattacks-hermes-agent/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: