By Adam Swan
Publication Date: 2026-10-08 06:37:00
Summary
Threat actors are actively exploiting two zero-day vulnerabilities in Citrix NetScaler appliances to obtain root-level access. The campaign involves deploying custom PHP web shells such as WHIPSHOT and a Python-based tunneling tool known as SLAPSHOT. These utilities allow attackers to perform internal reconnaissance and steal credentials by proxying traffic into protected network environments.
Investigation
Mandiant and Google Threat Intelligence Group identified exploitation of CVE-2026-88772 and CVE-2026-88771 in late September 2026. Researchers found that attackers use malformed DTLS record headers to trigger heap memory corruption in the NetScaler Packet Processing Engine. Forensic evidence also revealed modified httpd.conf files used for persistence and SUID permissions applied to /bin/sh to retain root privileges.
Mitigation
Organizations should prioritize installing the latest Citrix builds for supported NetScaler…



