Hackers Exploit Citrix NetScaler Zero-Day to Gain Root Access and Deploy Web Shells
Attackers exploit Citrix NetScaler zero-day CVE-2026-88772 for root access and PHP web shells.
Mandiant and Google’s Threat Intelligence Group say attackers have exploited Citrix NetScaler zero-day CVE-2026-88772 since at least early September 2026 against organizations in North America and Europe. The CVSS 9.5 memory overflow is triggered by malformed DTLS records on UDP port 443 and gives unauthenticated root execution on ADC and Gateway appliances when DTLS is enabled. Operators then installed WHIPSHOT PHP web shells, deployed the SLAPSHOT TCP tunneler, and set the SUID bit on /bin/sh. Citrix fixes are 14.1-73.37 and 13.1-64.23 or later, and CVE-2026-88771 has also been exploited in the wild.
- CVE-2026-88772 is a pre-authentication DTLS memory overflow scored CVSS 9.5.
- Exploitation gives root on FreeBSD-based NetScaler ADC and Gateway appliances.
- Attackers then deployed WHIPSHOT web shells and the SLAPSHOT tunneler.
- Patch to 14.1-73.37 or 13.1-64.23; CVE-2026-88771 is also exploited.
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article626 words · extracted from gbhackers.com · click to collapse
Threat actors are actively exploiting a critical zero-day vulnerability in Citrix NetScaler, identified as CVE-2026-88772, to gain unauthenticated root-level access to vulnerable Application Delivery Controller (ADC) and Gateway appliances.
After the initial compromise, they deploy custom PHP web shells and tools to tunnel within the internal network. Mandiant Consulting and the Google Threat Intelligence Group (GTIG) reported that this campaign has been active since at least early September and has impacted organizations in North America and Europe.
This vulnerability affects NetScaler ADC and NetScaler Gateway deployments that have Datagram Transport Layer Security (DTLS) enabled, which is the default setting on VPN virtual servers.
Citrix assigned a CVSS v4 score of 9.5 to this bug and confirmed that it has been exploited in attacks against systems that have not applied mitigations.
Citrix NetScaler Zero-Day
CVE-2026-88772 is a memory overflow issue in the NetScaler Packet Processing Engine (NSPPE). Attackers can exploit the vulnerability by sending malformed or fragmented DTLS record headers during the pre-authentication cryptographic handshake over UDP port 443.
This crafted traffic can corrupt heap memory in the packet-processing component, redirecting the execution flow and enabling arbitrary shellcode execution with root privileges on the FreeBSD-based operating system. As a result, attackers can compromise exposed appliances without needing valid NetScaler credentials.
Mandiant observed two key exploitation artifacts: an SSL handshake failure logged as DTLSv1.0 with the reason “Handshake failure – Internal Error,” followed by an NSPPE termination or crash recorded in `/var/log/messages`. Administrators should treat the combination of these events as a high-priority intrusion signal.
After compromising the system, the attackers modified `/etc/httpd.conf` to allow non-script files to be executed as PHP files. In some instances, web shells were hidden behind `.deb` and `.sig` file extensions within the NetScaler VPN script directories.
The attackers employed two persistence patterns:
- Registering `.deb` files as PHP through an `AddHandler application/x-httpd-php .deb` directive.
- Mapping seemingly benign requests for `/vpn/media/*.ico` to malicious `.sig` files using `AliasMatch`, allowing the system to treat `.sig` files as PHP.
The campaign utilized WHIPSHOT, a custom PHP web shell that receives Base64-encoded commands via native HTTP headers, suppresses errors, and can return misleading HTTP 404 responses to disguise malicious activities.
The web shell used headers such as `HTTP_NSC_LDAP`, `HTTP_NSC_CLIENTTYPE`, and chunked `HTTP_X_UX` values for command-and-control operations.
Additionally, attackers deployed SLAPSHOT, a Python TCP tunneler that creates a loopback proxy on an ephemeral port, enabling access to internal hosts. This tool can open, send to, receive from, and close arbitrary TCP sessions, facilitating reconnaissance, credential theft, and lateral movement.
To maintain elevated privileges after the initial exploit, operators set the SUID bit on `/bin/sh` using the command `chmod u+s /bin/sh`. Then they restarted either the appliance or the Apache service. A shell with permissions such as `-rwsr-xr-x` is a serious indicator of compromise.
Citrix has released fixed versions, and organizations using affected appliances should urgently upgrade to NetScaler version 14.1-73.37 or later, or 13.1-64.23 or later. Both CVE-2026-88772 and the separate CVE-2026-88771 have been observed in real-world attacks.
If immediate patching is not operationally feasible, defenders should disable DTLS where possible and block inbound UDP traffic on port 443 at an upstream firewall.
These measures may reduce exposure to CVE-2026-88772 but do not substitute for patching or protect against the second actively exploited vulnerability.
Organizations that find evidence of compromise should isolate the affected appliance, halt high-availability configuration synchronization, preserve the system state for forensic analysis if possible, rotate NetScaler and integration credentials after patching, and investigate downstream Citrix infrastructure for lateral movement.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.