Google Warns of Hackers Actively Exploiting Citrix 0-Day Vulnerabilities to Deploy Web Shells
Attackers are exploiting two critical Citrix NetScaler zero-days to deploy WHIPSHOT web shells and tunnel inward.
Mandiant and Google Threat Intelligence Group say attackers have exploited Citrix NetScaler zero-days CVE-2026-88772 and CVE-2026-88771 since at least early September 2026. Both flaws are scored CVSS 9.5; exploitation bypasses authentication, crashes the packet engine, and gives root on the FreeBSD-based appliance. Operators install the WHIPSHOT PHP web shell and the SLAPSHOT Python tunnel to reach internal hosts, steal credentials, and retain root with a setuid /bin/sh. Victims include government, finance, technology, education, and professional services in North America and Europe; fixed builds include NetScaler 14.1-73.37 and 13.1-64.23 and later.