Unknown attackers are using critical Citrix NetScaler ADC and Gateway zero-day flaws, CVE-2026-88771 and CVE-2026-88772, to compromise organizations across government, financial services, education, and legal and professional services sectors in North America and Europe[2][10][11].
The exploitation began weeks before Citrix publicly disclosed and patched the bugs, with Google’s Threat Intelligence Group and Mandiant reporting that the campaign has been underway since at least early September[2][11][12].
Citrix acknowledged that both issues were already being actively exploited when it published a security bulletin covering eight NetScaler vulnerabilities on Sunday[3][10][12].
CVE-2026-88771 arises from improper input validation in NetScaler ADC and Gateway and allows unauthenticated remote attackers to execute arbitrary commands on affected appliances, including those running default configurations[1][10][14].
The flaw impacts customer-managed NetScaler deployments running versions prior to 14.1-73.37 and 13.1-64.23, including corresponding FIPS and NDcPP builds[1][3][13].
Citrix and several national CERTs have assigned CVSS v4 base scores of 9.5 to the vulnerability, underscoring its critical severity[3][4][14].
CVE-2026-88772 is a memory overflow in NetScaler’s DTLS implementation that can lead to remote code execution or denial of service when DTLS is enabled, which is the default on VPN virtual servers, and it likewise carries a 9.5 CVSS score[3][8][10].
Google’s advisory describes how exploitation of CVE-2026-88772 can bypass authentication and trigger an unhandled termination in the NetScaler packet processing engine to gain initial root-level access[2][11].
In post-compromise activity, Mandiant analysts identified previously unseen custom malware, including WHIPSHOT, a PHP web shell, and SLAPSHOT, a Python-based tunneling tool designed to proxy traffic deeper into victim networks[2][11].
WHIPSHOT disguises itself as a Debian package and hides Base64-encoded command-and-control payloads inside native HTTP headers, functioning as an HTTP transport bridge for SLAPSHOT, which accepts commands and forwards arbitrary TCP streams to internal hosts[2][8].
The tools support commands such as open, push, pull, exch, close, and ping to manage network sessions, and have been used by the intruders to conduct manual internal reconnaissance and steal credentials via the proxy channel[2][8][11].
Security researchers have criticized Citrix for the delay between discovering the compromise and notifying customers, noting that incident responders uncovered the vulnerabilities while investigating already-breached environments.
Benjamin Harris, founder and CEO of exposure management firm watchTowr, told The Register that only Citrix can explain why it waited to disclose actively exploited NetScaler flaws and argued the company has a history of slow vulnerability publication.
Mandiant Consulting CTO Charles Carmakal has urged NetScaler customers to prioritize hunting for evidence of compromise—such as web shells or other malicious files—before applying upgrades or patches, warning that remediation may not eject a deeply embedded threat actor.
Citrix’s bulletin makes clear that exploits against unmitigated deployments have already been observed in the wild, and multiple security vendors report seeing active scanning and exploitation attempts against exposed appliances[3][5][10].
Google notes that the NetScaler incidents highlight a broader trend of threat actors targeting edge devices such as application delivery controllers, VPN gateways, and firewalls to gain initial access while bypassing traditional endpoint defenses[2].
Its threat intelligence team counted security and networking appliance vulnerabilities as roughly half of enterprise-related zero-days disclosed in 2025, reflecting attackers’ growing focus on internet-facing infrastructure[2].
NetScaler has faced multiple critical flaws in recent years, with attackers repeatedly exploiting newly disclosed bugs and Citrix periodically releasing large batches of fixes for the product[10][14].
Organizations running customer-managed NetScaler ADC or Gateway should apply the latest fixed builds, restrict external exposure where possible, and continuously monitor for anomalous traffic and persistence mechanisms on their edge appliances[3][4][10].
References
- NVD-CVE-2026-88771 – NIST
- Defending Against Active Exploitation of Citrix NetScaler …
- Article Record Type: Security Bulletin
- Critical vulnerabilities in Citrix NetScaler ADC and …
- Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation
- WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign
- Citrix NetScaler RCE zero-days exploited globally for …
- Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
- Citrix NetScaler exploitation began days before public …
- CVE-2026-88771 | Tenable®
- NetScaler admins told to patch critical zero-days in ADC and …
