Critical Citrix ADC, Gateway Zero-Days Under Active Attack
Key Takeaways Two critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances are under active exploitation. The flaws, CVE-2026-88772 and CVE-2026-88771, allow unauthenticated...
Key Takeaways
- Two critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances are under active exploitation.
- The flaws, CVE-2026-88772 and CVE-2026-88771, allow unauthenticated root-level access and remote code execution.
- Organizations across North America and Europe, spanning government, finance, technology, and education sectors, have been targeted.
- Attackers deploy stealthy web shells (WHIPSHOT) and a tunneling tool (SLAPSHOT) for reconnaissance and lateral movement.
- Patches are available, and immediate updates are strongly recommended by Citrix and security researchers.
Cybersecurity researchers from Google have issued an urgent warning regarding the active exploitation of two critical zero-day vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances. Threat actors are leveraging these flaws to achieve root access, deploy sophisticated web shells, and infiltrate target networks across North America and Europe.
Table Of Content
The ongoing campaign, which Google said has been active since at least early September 2026, has impacted a diverse range of sectors, including government entities, financial services firms, technology companies, educational institutions, and legal and professional services organizations. The findings were jointly reported by Mandiant Consulting and the Google Threat Intelligence Group (GTIG).
The Vulnerabilities: CVE-2026-88772 and CVE-2026-88771
The attackers are exploiting two distinct vulnerabilities: CVE-2026-88772, a critical memory-overflow flaw, and CVE-2026-88771, an unauthenticated remote code execution vulnerability stemming from improper input validation. Both have been assigned a CVSS score of 9.5 by Citrix, confirming their severe impact and active exploitation.
CVE-2026-88772 specifically targets appliances where Datagram Transport Layer Security (DTLS) is enabled. This feature is a default setting on VPN virtual servers, making a wide range of devices susceptible. Exploitation of this flaw enables attackers to bypass authentication and trigger an unhandled termination of the NetScaler Packet Processing Engine (NSPPE). This critical event grants adversaries root-level access to the underlying FreeBSD operating system.
Once an appliance is compromised, attackers manipulate the httpd.conf web server configuration file. This modification allows seemingly innocuous file types to be executed as PHP scripts, a technique used to establish persistence and deploy malicious payloads.
Citrix Zero-Days Facilitate Web Shell and Tunneling Tool Deployment
During observed intrusions, threat actors have been seen configuring .deb package files and .sig signature files to be interpreted as executable PHP scripts. They also employ icon aliases, a deceptive tactic where a request for a harmless-looking .ico file can covertly trigger a hidden web shell.
WHIPSHOT Web Shell and SLAPSHOT Tunneling Tool
The campaign deploys a newly identified PHP web shell named WHIPSHOT. This malware is designed for stealth, embedding Base64-encoded command-and-control (C2) data within legitimate-appearing HTTP headers. This method helps the attackers camouflage malicious traffic within normal web requests. WHIPSHOT is capable of relaying commands and results while simultaneously returning deceptive HTTP 404 Not Found responses, which can mislead administrators during log analysis.
Researchers also identified SLAPSHOT, a Python-based tunneling tool. SLAPSHOT establishes a listener on a local loopback port, acting as a proxy for arbitrary TCP traffic from the compromised NetScaler device into the internal network. This capability empowers attackers to conduct internal reconnaissance, connect to other internal hosts, steal credentials, and facilitate lateral movement within the victim’s environment. In at least one incident, the proxy was reportedly used for manual internal reconnaissance and credential theft.
To maintain root-level access, attackers set the setuid permission bit on /bin/sh. This ensures the system shell executes with elevated privileges, even when commands originate from a lower-privileged web server process. In some cases, to activate these malicious configuration changes, attackers rebooted the appliance or restarted the Apache web server.
GreyNoise observed attempted exploitation of these vulnerabilities even before Citrix publicly disclosed them, noting activity from IP address 149.104.78.141 on September 24. This highlights the persistent risk posed by internet-facing edge appliances, which often lack comprehensive endpoint detection coverage while offering direct access to sensitive internal networks.
What You Should Do
- Immediately Apply Patches: Urgently update affected NetScaler systems. Citrix has released fixed versions, including NetScaler 14.1-73.37 and later, as well as NetScaler 13.1-64.23 and later. Equivalent fixed FIPS builds are also available.
- Inspect Configuration Files: Thoroughly examine
/etc/httpd.conffor any suspiciousAddHandler,AliasMatch, and PHP directives. - Scan VPN Script Directories: Search VPN script directories for PHP code hidden within
.debor.sigfiles. - Check for SLAPSHOT Indicators: Look for the presence of
/tmp/.uxdportor/tmp/.uxdlock, which are potential indicators of SLAPSHOT activity. - Monitor for Anomalies: Treat a setuid-enabled
/bin/sh, unexpected NSPPE crashes, DTLS handshake failures, and unusual requests to/vpn/media/or/vpn/scripts/as high-priority compromise indicators. - Review Logs: Scrutinize web logs for large or slow HTTP 404 responses, which could indicate hidden web-shell output.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.