Attackers have exploited two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to compromise government agencies, financial services firms, educational institutions, and legal and professional services organizations across North America and Europe. The exploitation campaign began in early September, weeks before Citrix publicly disclosed the vulnerabilities.
CVE-2026-88771 is a remote code execution flaw that allows an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service, particularly when DTLS is enabled, which is the default setting for VPN virtual servers. Both vulnerabilities received critical CVSS scores of 9.5.
Security researchers observed attempts to exploit CVE-2026-88771 against a Citrix NetScaler Gateway as early as September 24. The broader campaign leveraging CVE-2026-88772 has been active since at least early September. Citrix confirmed that exploitation of both CVEs on unmitigated NetScaler deployments has been observed.
The vulnerabilities were initially discovered during incident response and forensic investigations at organizations that had already been compromised, indicating that both the exploitation and Citrix's awareness of the issues predated public disclosure. This has raised concerns among security experts regarding the vendor's timeline for disclosing critical vulnerabilities, especially those under active attack.
Attackers in this campaign have deployed custom malware to establish persistent root access and proxy traffic into internal corporate networks. This post-exploit toolkit includes WHIPSHOT, a PHP web shell, and SLAPSHOT, a TCP tunneling tool written in Python.
WHIPSHOT is designed to appear as a Debian package and conceals Base64-encoded command-and-control payloads within native HTTP headers. It functions as an HTTP transport bridge for SLAPSHOT. SLAPSHOT, in turn, accepts commands from WHIPSHOT and forwards arbitrary TCP streams to internal hosts.
The supported commands for SLAPSHOT include `open` to establish an outbound TCP socket, `push` to write data to an open session, `pull` to read data from an open session socket, `exch` for sending and receiving command-and-control data, `close` to terminate a network session, and `ping` for basic health checks. In at least one observed intrusion, the threat actor utilized this proxy to conduct internal reconnaissance and steal credentials.
While no specific attribution has been made public, historically, NetScaler vulnerabilities have been exploited by both state-sponsored groups and ransomware operators. The continued targeting of edge devices like application delivery controllers, VPN gateways, and firewalls is a persistent trend, as these devices offer direct access from the internet to corporate networks, often bypassing endpoint detection and other security layers.
Organizations using Citrix NetScaler ADC and NetScaler Gateway appliances are strongly advised to apply the security updates immediately. However, security experts also recommend thoroughly examining systems for signs of compromise *before* patching. If evidence of web shells or other malicious files is found, it is crucial to preserve evidence and investigate the scope of the compromise, as patching alone may not remove the threat actor from the environment.






