Security researchers have detected malicious activities exploiting a recently patched vulnerability in Citrix NetScaler ADC and Gateway devices. This breach is impacting organizations across North America and Europe, notably in the government, finance, technology, education, and legal sectors.
Discovering the Vulnerability
In September 2026, Mandiant Consulting along with Google’s Threat Intelligence Group identified these attacks targeting several industries. The exploitation leverages CVE-2026-88772, a flaw that bypasses authentication and disrupts the NetScaler Packet Processing Engine (NSPPE) to gain root-level access.
Attackers have used this vulnerability to deploy novel toolkits, including new PHP web shells like WHIPSHOT, which are capable of hiding encoded command-and-control payloads within HTTP headers.
Deployment and Methodology
Additionally, a Python-based tunneling tool named SLAPSHOT is being employed to redirect traffic into internal networks for reconnaissance and credential theft. In one instance, attackers utilized this setup to manually gather internal information and credentials.
The flaw, identified as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol, allows attackers to execute arbitrary shellcode on the FreeBSD platform used by NetScaler devices. This vulnerability has a CVSS score of 9.5, indicating its critical nature.
Impact and Countermeasures
Following exploitation, attackers modify configuration files to deploy WHIPSHOT and SLAPSHOT, which involve crafting deceptive extensions for web shells. These activities are concealed under seemingly benign file types, complicating detection efforts.
Post-attack, these web shells enable direct command execution and maintain persistence on compromised devices, with WHIPSHOT executing encoded commands from HTTP headers. SLAPSHOT acts as a bridge within internal networks, facilitating lateral movements and data theft.
Implications and Future Outlook
This incident highlights the ongoing risk posed by edge devices, which remain attractive targets due to their exposure to the internet and lack of endpoint detection. Such appliances often store credentials that can be exploited for deeper network infiltration.
GreyNoise has reported an increase in cyber activities related to this vulnerability, with a marked escalation in exploitation attempts starting September 28, 2026. These activities are primarily aimed at recruiting botnets and brokering access.
The evolving threat landscape necessitates rigorous security measures and vigilance to safeguard against such vulnerabilities. Organizations are urged to apply patches promptly and enhance monitoring of edge devices to mitigate similar threats in the future.
