WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign

WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign

By Pierluigi Paganini
Publication Date: 2026-09-30 07:25:00

WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign

Pierluigi Paganini
September 30, 2026

Mandiant and GTIG detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access.

Mandiant and Google Threat Intelligence Group caught active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances in late September 2026. The bug, tracked as CVE-2026-88772 (CVSS score of 9.5), has been exploited in attacks in the wild since at least early September, hitting government, financial services, education, and legal services organizations across North America and Europe. Citrix disclosed a second zero-day being exploited alongside it, CVE-2026-88771.

CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service, and it affects appliances with DTLS enabled. That’s particularly relevant for…