Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
Actively exploited Citrix NetScaler zero-days CVE-2026-88772/88771 give attackers root access; Mandiant uncovers WHIPSHOT web shells and SLAPSHOT tunneler in ongoing campaign.
In late September 2026, Mandiant and Google Threat Intelligence identified active in-the-wild exploitation of zero-day CVE-2026-88772 in Citrix NetScaler ADC and NetScaler Gateway, ongoing since at least early September. The flaw bypasses authentication and triggers unhandled termination of the NetScaler Packet Processing Engine to achieve root-level shellcode execution on the underlying FreeBSD platform. Impacted organizations span North America and Europe across government, financial services, education, legal, and professional services sectors. The actor deploys the custom WHIPSHOT PHP web shell, which disguises Base64-encoded C2 payloads in HTTP headers, and the SLAPSHOT Python tunneler for internal reconnaissance and credential theft; a second zero-day, CVE-2026-88771, is also actively exploited per vendor disclosure.