Security & privacy

NetScaler vulnerabilities exploited for root access and malware deployment

Threat actors are actively exploiting two critical Citrix NetScaler flaws to gain root access, deploy web shells, and pivot into internal networks across North America and Europe.

Unknown threat actors are actively exploiting two recently patched security flaws in Citrix NetScaler ADC and NetScaler Gateway appliances. Observed by Mandiant Consulting and Google Threat Intelligence Group in September 2026, these attacks target organizations in North America and Europe, impacting dozens of entities across government, financial services, and technology sectors.

What happened

The campaign leverages CVE-2026-88772 and CVE-2026-88771 to bypass authentication and gain initial footholds. Charles Carmakal, chief technology officer at Mandiant Consulting, warned of broad and opportunistic exploitation by various threat actors. The primary vulnerability, CVE-2026-88772, allows attackers to bypass authentication entirely. It triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE), granting the attacker root-level access to the underlying system.

Once inside, adversaries deploy a post-exploitation toolkit featuring previously unreported PHP web shells. One such shell, named WHIPSHOT, hides Base64-encoded command-and-control payloads within standard HTTP headers. A companion Python tool called SLAPSHOT acts as a TCP tunneler, proxying traffic into internal networks to facilitate reconnaissance and credential theft. In observed cases, attackers used this proxy to manually explore internal systems and steal credentials.

GreyNoise detected a surge in malicious activity linked to CVE-2026-88771 starting September 28, 2026. While the vulnerability mechanism overlaps with Google’s observations, the actors and tools differ, indicating multiple independent groups are exploiting these flaws. GreyNoise noted that mass reconnaissance has evolved into full-scale exploitation for botnet recruitment and access brokering.

How it works

CVE-2026-88772 is a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling within the NSPPE component. During the pre-authentication cryptographic handshake, the engine parses inbound DTLS record structures. Attackers send specially malformed or fragmented record headers, causing heap memory boundary corruption. This diverts control flow to execute arbitrary shellcode with root privileges on the FreeBSD platform.

After gaining access, the attacker installs a web shell by modifying httpd.conf files. This change allows the server to treat Debian software package (.deb) files as PHP scripts. The web shells are staged in directories like "/netscaler/gui/vpn/scripts/linux" with deceptive extensions. In some variants, attackers map HTTP requests for .ico images to executable .sig files, hiding malicious code behind seemingly benign image requests. Logs may show 404 errors for these requests, but with unusually long processing times and large response sizes, indicating hidden execution.

The malware establishes persistence by altering permissions for "/bin/sh" and rebooting the appliance. WHIPSHOT executes commands extracted from HTTP headers, while SLAPSHOT creates a bridge to internal hosts. If inactive for ten minutes, SLAPSHOT deletes its port and lock files to minimize forensic traces.

Key details

  • CVE-2026-88772 has a CVSS score of 9.5 and allows root-level access via DTLS handling flaws.
  • WHIPSHOT is a PHP web shell that hides C2 payloads in Base64-encoded HTTP headers.
  • SLAPSHOT is a Python-based TCP tunneler used for internal reconnaissance and lateral movement.
  • Attackers modify httpd.conf to execute .deb and .sig files as PHP scripts, disguising web shells.
  • Censys data from September 28, 2026, shows 42,735 hosts running NetScaler ADC or Gateway globally.
  • Multiple threat actors are exploiting these flaws for botnet recruitment and access brokering.

Why it matters

Edge devices like Application Delivery Controllers and VPN gateways are prime targets because they face the internet directly and often sit outside the coverage of endpoint detection and response tools. Compromising these appliances provides attackers with a privileged position to move laterally into internal networks. Since these devices often process or store credentials, a breach here can lead to widespread identity compromise and deeper network infiltration.

For software engineers and IT leads, this highlights the risk of relying solely on perimeter security. The use of legitimate-looking file extensions and HTTP headers makes detection difficult using traditional signature-based methods. The fact that multiple independent actors are exploiting these flaws suggests that unpatched systems will face continuous, automated scanning and exploitation attempts. Immediate patching and rigorous monitoring of edge device logs are essential to mitigate this threat.

What you can do

  • Apply the latest Citrix patches for CVE-2026-88772 and CVE-2026-88771 immediately.
  • Monitor httpd.conf files for unauthorized changes that enable PHP execution for non-standard file types.
  • Inspect web server logs for unusual 404 responses with high processing times or large payload sizes.
  • Check for the presence of WHIPSHOT or SLAPSHOT artifacts in "/netscaler/gui/vpn/scripts/linux".
  • Restrict internet-facing access to NetScaler management interfaces where possible.
  • Review authentication logs for signs of brute-force attempts or anomalous User-Agent strings containing Base64 data.

Tools from the Bytechap store

Keep reading

All stories