
Attackers Exploit Citrix NetScaler Flaw for Root Access
Attackers exploit Citrix NetScaler flaw CVE-2026-88772 to gain root access, deploying web shells WHIPSHOT and SLAPSHOT for internal reconnaissance, Mandiant and…
A newly patched security vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances is under active exploitation by unknown threat actors, giving them full root-level control of affected devices and enabling the deployment of previously unseen post-exploitation tools. The attacks, observed in September 2026 by Mandiant Consulting and Google Threat Intelligence Group (GTIG), have already compromised dozens of organisations across North America and Europe, targeting government, financial services, technology, education, and legal and professional services sectors.
At the centre of the campaign is CVE-2026-88772, a memory overflow bug in how the NetScaler Packet Processing Engine (NSPPE) handles Datagram Transport Layer Security (DTLS) handshakes. With a severity score of 9.5 out of 10, the flaw allows an unauthenticated attacker to send specially crafted or fragmented DTLS record headers that corrupt heap memory and divert control flow, ultimately executing arbitrary shellcode with root operating system privileges on the underlying FreeBSD platform. In short, a remote hacker can take complete control of the appliance without needing any login credentials.
Once in, the attackers modify the Apache httpd.conf configuration file so that Debian software package files with a .deb extension are treated as PHP scripts. They then drop a series of lightweight PHP web shells into the /netscaler/gui/vpn/scripts/linux/ directory, disguising them as ordinary files. The most notable of these is WHIPSHOT, a web shell that extracts Base64-encoded commands and payloads directly from HTTP headers, executes them, and returns the results, effectively hiding its command-and-control traffic inside normal-looking web requests. Alongside WHIPSHOT, the attackers deploy a Python-based TCP tunneler called SLAPSHOT, which acts as a bridge into the internal network: it accepts commands from WHIPSHOT and forwards arbitrary TCP streams to hosts inside the victim’s environment, facilitating lateral movement, credential theft, and reconnaissance. To cover its tracks, SLAPSHOT removes its port and lock files and terminates its own process if no active sessions are received for ten minutes.
The infection chain also involves a covert configuration hook that maps incoming HTTP requests ending in .ico under /vpn/media/ to a matching .sig file in the web shell directory. For example, a request to /vpn/media/e6ee7c85.ico is silently served by the PHP web shell e6ee7c85.sig, making it appear as a simple image fetch. Google noted that in at least one case, web server access logs showed GET requests returning HTTP 404 responses but with elevated processing durations and multi-kilobyte response sizes, while subsequent attempts to access non-existent .sig files generated missing-file errors in httperror-vpn logs, suggesting the attackers managed similar web shells across multiple compromised environments.
Adding to the urgency, GreyNoise reported a sharp increase in exploitation attempts targeting a second vulnerability, CVE-2026-88771, beginning September 28, 2026, with a surge around 10:30 p.m. EDT the same day. CERT-EU also issued an alert, describing attackers filling HTTP logs with Base64-encoded payloads in the User-Agent string and hammering authentication logs in the hope that their exploit trigger is the last log line when a specific error function is called. The intelligence firm noted that while the exploitation mechanisms overlap with those observed by Google, the actors and tooling differ, indicating multiple independent groups are now actively exploiting these flaws. According to Censys, as of September 28 there were 42,735 hosts and 323,527 web properties running NetScaler ADC or Gateway, with the United States accounting for 32% of the exposed hosts, followed by Germany at 13% and the Netherlands, United Kingdom, and Switzerland at around 4% each; many of these are virtual appliances running in public clouds from Microsoft and Amazon.
For any organisation relying on edge devices like application delivery controllers and VPN gateways, the campaign is a stark reminder that these internet-facing appliances sit outside the reach of traditional endpoint detection and response tools and often store or process credentials that can unlock deeper network access. Immediate patching is the most critical defence. Organisations managing their own infrastructure can strengthen their posture by working with security-focused IT partners that offer continuous monitoring and rapid incident response. For those who need expert guidance, AEU-I provides security-first infrastructure and consulting services that help businesses identify exposed appliances, apply patches promptly, and harden configurations against such intrusions.
Come Proteggerti
- If your business uses Citrix NetScaler for remote access, contact your IT partner immediately and ask them to install the latest security update.
- Watch for any unusual behaviour on your company’s VPN or login portal, such as unexpected prompts or slow responses, and report it to your IT team.
- Ask your web hosting or IT provider if they monitor edge appliances for unauthorized configuration changes, especially to files like httpd.conf.
- Use a DNS security service that blocks known malicious websites to add a layer of protection even if an appliance is compromised.
- If you manage servers yourself, restrict access to the management interface to only the IP addresses that absolutely need it and enable two-factor authentication.
Vulnerabilità e Soluzioni
- CVE-2026-88771 Authentication bypass flaw in Citrix NetScaler exploited to deliver web shells; patched by Citrix. Vedi la soluzione e i dettagli →
- CVE-2026-88772 Memory overflow in Citrix NetScaler DTLS handling that allows unauthenticated root-level code execution; patched by Citrix. Vedi la soluzione e i dettagli →
I Termini Spiegati
- NetScaler ADC A network appliance from Citrix that balances traffic across servers and provides secure remote access for employees.
- DTLS Datagram Transport Layer Security, a protocol that encrypts data sent over fast but connectionless UDP connections.
- web shell A small script placed on a server that lets an attacker remotely run commands and control the machine through a web browser.
- PHP A programming language commonly used to build dynamic websites and run server-side tasks.
- Base64 A method of converting data into plain text so it can be hidden inside normal-looking web traffic and bypass security filters.
- command-and-control (C2) A server controlled by attackers that sends instructions to malware on compromised systems.
- tunneler A tool that secretly creates a pathway through a network’s defences so an attacker can reach internal systems from outside.