Attackers exploited two zero-day vulnerabilities in Citrix NetScaler ADC and Gateway for at least three weeks before Citrix disclosed them on Sunday 27 September. Mandiant which investigated the intrusions, said the campaign had been running since at least early September. It said the victims were likely organisations in North America and Europe in government, financial services, technology and education as well as legal and professional services.
The two flaws, CVE-2026-88771 and CVE-2026-88772, both scored 9.5 under CVSS v4.0. They were among eight vulnerabilities in Citrix bulletin CTX697096. Citrix released fixed builds 14.1-73.37 and 13.1-64.23 of NetScaler ADC and Gateway with matching FIPS and NDcPP releases. CISA added both CVEs to its Known Exploited Vulnerabilities catalogue the same day.
Citrix said CVE-2026-88771, an input validation flaw, lets an unauthenticated attacker run arbitrary commands on any NetScaler ADC or Gateway including in the default configuration. CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service when DTLS is enabled. Citrix said DTLS is on by default on VPN virtual servers.
In the days before the bulletin, IT suppliers, CERTs and national agencies privately warned NetScaler owners about two unpatched flaws and in some cases told them to shut the appliances down. Citrix’s Sunday blog post carried a noindex tag which tells search engines to leave a page out of their results.
How the DTLS exploit reaches root
Mandiant’s investigation centred on CVE-2026-88772. Google Threat Intelligence Group said the exploit arrives over UDP/443 as malformed DTLS records during the pre-authentication handshake. It corrupts heap memory in the NetScaler Packet Processing Engine and gives the attacker root on the underlying FreeBSD system. GTIG said it does not hold the exploit code and based its description on frontline telemetry.
GreyNoise said a single IP address, 149.104.78.141, attempted a CVE-2026-88771 command injection against one of its sensors on 24 September, more than three days before disclosure. The attempt failed. Its payload would have set the setuid bit on /bin/sh, planted a hidden PHP web shell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver and aliased a non-existent file, receiver.min.css, to it.
Mandiant’s interim mitigations are disabling DTLS where possible and blocking inbound UDP/443 at an upstream firewall. Google said those steps apply only to CVE-2026-88772. CVE-2026-88771 does not depend on an optional feature and the published guidance lists no workaround for it beyond the fixed builds.
WHIPSHOT and SLAPSHOT, Two New Malware Families
Mandiant said the attackers rewrote the appliance’s web server configuration so that harmless-looking file types would execute as PHP. In one intrusion /etc/httpd.conf was changed to run .deb files as scripts from the directory that normally serves the Linux VPN client plug-in. In others an AliasMatch rule mapped requests for .ico images under /vpn/media/ to PHP files with a .sig extension. In Mandiant’s example, a request for e6ee7c85.ico executed a web shell named e6ee7c85.sig.
Some shells returned fake HTTP 404 responses while still sending back multi-kilobyte bodies. To keep root access, the attackers set the setuid bit on /bin/sh and then rebooted the appliance or restarted the web server to load the changes.
Mandiant said it found two malware families it had not seen before. WHIPSHOT is a PHP web shell disguised as a Debian package. It takes Base64-encoded data from HTTP request headers and passes it to SLAPSHOT, a Python TCP tunnel that links the NetScaler to internal hosts. Mandiant said the attackers used the tunnel in at least one intrusion for manual reconnaissance and credential theft. SLAPSHOT deletes its port and lock files and exits after 10 minutes of inactivity.
Mandiant has not attributed the campaign to any group.
It said the attacker requested web shell files that no longer existed on one appliance which may indicate the same operator was running similar shells in several victim networks.
Shadowserver Counts More Than 23,000 Exposed NetScalers
Shadowserver tracks more than 23,000 internet-facing IP addresses with NetScaler fingerprints roughly 22,000 ADC and 1,500 Gateway instances. It said it cannot tell how many of them are honeypots, already patched or configured in a vulnerable way.
Attackers began exploiting CVE-2026-3055 days after its March patch. CVE-2026-19490, an authentication bypass fixed in mid-August, came under attack in early September. It’s reported that 26 Citrix vulnerabilities have been added to CISA’s KEV catalogue since November 2021. CISA gave US federal agencies until 30 September to secure appliances affected by the two new flaws.
Evidence Before the Patch
CISA advised checking for compromise before updating where possible and warned that the update may destroy forensic evidence. For appliances running as VPX virtual machines, Mandiant recommended a full snapshot including memory before any reboot.
Mandiant’s hunting guidance lists these indicators:
- AddHandler or AddType lines in /etc/httpd.conf that register .deb, .sig or other non-PHP extensions as PHP, plus AliasMatch rules pointing /vpn/media/ or /vpn/theme/ at script directories
- Plain-text files or PHP code in /var/netscaler/gui/vpn/scripts/linux/ and the other client plug-in folders, which should hold only compiled binaries
- The files /tmp/.uxdport or /tmp/.uxdlock, left behind by SLAPSHOT
- A setuid bit on /bin/sh, shown as -rwsr-xr-x with root ownership
- Python processes launched with nohup or carrying Base64-encoded payloads
- A DTLSv1.0 SSL_HANDSHAKE_FAILURE with the reason “Handshake failure-Internal Error”, followed within minutes by an NSPPE crash in /var/log/messages, a log NetScaler does not forward with ns.log by default
- GreyNoise’s indicators, the hidden .ctxs.receiver file and connections from 149.104.78.141
Citrix has published generic indicators of compromise through NetScaler Console. It warned that they “might fail to identify actual compromises” and advised customers to engage experienced forensic investigators.
The published response guidance recommends keeping configuration synchronisation disabled in high-availability pairs until both nodes have been checked, so a compromised node cannot copy a tampered httpd.conf to its partner. After patching, it calls for ending active Gateway, VPN and administrative sessions and rotating NetScaler admin passwords, LDAP bind accounts, RADIUS shared secrets, SSH keys and TLS certificates with their private keys. It also calls for checking StoreFront servers and Delivery Controllers connected to the appliance for unexpected logons.
Reporting to CERT-SE
CERT-SE issued an alert on 27 September recommending prompt updates and a careful search for signs of intrusion. The agency can be reached around the clock on 010-382 80 00. Incidents can also be reported to Citrix.
As of 1 October, no count of confirmed victims had been published and no affected organisation had been named. How the attackers obtained the exploits has not been disclosed. No Nordic victim has been publicly reported.
References
- Hackers Exploit Citrix NetScaler Zero-day to Deploy Web Shells
- CISA Orders Feds to Patch Exploited Citrix Flaws by Wednesday
- Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 to CVE-2026-88778
- Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
- Swarming Against Citrix 0-Day Exploitation
- CISA Adds Two Known Exploited Vulnerabilities to Catalog
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC and Gateway
- Kritiska sårbarheter i Citrix NetScaler ADC och Citrix NetScaler Gateway
This post is also available in:

