Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances. 🚨 We have observed evidence that organizations in North America and Europe across various sectors, including government, financial services, technology, education, and legal services, were likely impacted by this ongoing exploitation campaign since early September.
Key Findings
- Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE), establishing initial root-level access.
- The actor’s post-exploitation toolkit reveals custom PHP web shells, such as WHIPSHOT, capable of disguising Base64-encoded command-and-control (C&C) payloads within native HTTP headers.
- A novel companion Python tunneler, SLAPSHOT, proxies traffic into internal networks for reconnaissance and credential theft.
Threat Actor Behavior
In at least one observed intrusion, the threat actor routed traffic through this proxy to manually conduct internal reconnaissance and credential theft. To maintain persistent root-level execution for its web shells, the threat actor leveraged lightweight installer web shells to assert the setuid (Set User ID) bit on the /bin/sh executable. For example, clients accessing /vpn/media/e6ee7c85.ico would be served by the dropped PHP web shell e6ee7c85.sig.
Recommendations
Organizations that have not yet applied the latest security updates should immediately assess their exposure and risk. Mandiant recommends implementing the latest Citrix build that addresses the in-scope vulnerabilities:
- NetScaler 14.1 Track: Upgrade to version 14.1-73.37 and later releases.
- NetScaler 13.1 Track: Upgrade to version 13.1-64.23 and later releases of 13.1.
For confirmed or suspected compromise, isolate affected NetScaler appliances from the network and disable configuration synchronization until both nodes have been validated to prevent a compromised node from replicating malicious changes. If immediate patching is not possible, organizations should implement targeted controls to reduce the exposed attack surface, such as disabling DTLS where operationally feasible.
In this campaign, the exploit payload is delivered over UDP/443 using Datagram Transport Layer Security (DTLS). Installing a fixed NetScaler build remains essential to address both vulnerabilities.