Google has issued a warning about active exploitation of two major zero-day vulnerabilities in Citrix NetScaler systems. These vulnerabilities are being leveraged by hackers to gain unauthorized access and install web shells, potentially compromising organizational networks.
The vulnerabilities, affecting entities across North America and Europe, have been identified in critical sectors such as government, finance, technology, education, legal, and professional services. The campaign has been ongoing since early September 2026, according to Mandiant Consulting and Google Threat Intelligence Group (GTIG).
Understanding the Citrix Exploits
The attackers are targeting two specific vulnerabilities: CVE-2026-88772, a critical memory overflow issue in Citrix NetScaler ADC and Gateway appliances, and CVE-2026-88771, a remote code execution flaw due to improper input validation. Both vulnerabilities have been given a CVSS score of 9.5, highlighting their severity.
These vulnerabilities allow attackers to bypass authentication, causing unexpected terminations in the NetScaler Packet Processing Engine (NSPPE) and enabling root-level access to the system. Once inside, attackers alter the configuration of the web server to execute malicious scripts disguised as regular files.
Deployment of Malicious Web Shells
In observed cases, attackers have manipulated .deb packages and .sig signature files to execute PHP code. They have also used icon aliases to disguise web shell executions as harmless file requests. A new PHP web shell identified as WHIPSHOT is being used to embed command-and-control data within legitimate HTTP headers, thus blending malicious activities with normal traffic.
Another tool, a Python-based tunneling tool named SLAPSHOT, has been employed to redirect traffic from compromised devices to internal networks, facilitating further reconnaissance and credential theft.
Protective Measures and Recommendations
Organizations are urged to update their NetScaler systems immediately. Citrix has released fixed versions, including NetScaler 14.1-73.37 and later, and NetScaler 13.1-64.23 and later. Administrators should scrutinize configuration files for suspicious activity and investigate any unusual system behavior as potential compromise indicators.
Security teams should be vigilant for unexpected NSPPE crashes, unusual HTTP requests, and other indicators of compromise. Ensuring endpoint detection coverage for internet-facing appliances is crucial, as these devices provide direct access to sensitive environments.
GreyNoise research indicates that exploitation attempts began even before Citrix publicly disclosed these vulnerabilities, underscoring the urgent need for proactive security measures. Organizations should integrate threat intelligence tools to enhance their security operations and reduce response times.
