Citrix NetScaler Zero-Days Under Active Exploitation

Citrix NetScaler Zero-Days Under Active Exploitation

By Adam Swan
Publication Date: 2026-10-08 06:37:00

Summary

Threat actors are actively exploiting two zero-day vulnerabilities in Citrix NetScaler appliances to obtain root-level access. The campaign involves deploying custom PHP web shells such as WHIPSHOT and a Python-based tunneling tool known as SLAPSHOT. These utilities allow attackers to perform internal reconnaissance and steal credentials by proxying traffic into protected network environments.

Investigation

Mandiant and Google Threat Intelligence Group identified exploitation of CVE-2026-88772 and CVE-2026-88771 in late September 2026. Researchers found that attackers use malformed DTLS record headers to trigger heap memory corruption in the NetScaler Packet Processing Engine. Forensic evidence also revealed modified httpd.conf files used for persistence and SUID permissions applied to /bin/sh to retain root privileges.

Mitigation

Organizations should prioritize installing the latest Citrix builds for supported NetScaler…