// 3 ZERO-DAY · 6 CVE · 6 EXPLOIT IN THE LAST 24H→
Two critical Citrix NetScaler vulnerabilities were exploited as zero-days starting September 1, 2026, three weeks before Citrix published its security bulletin on September 27. Google Threat Intelligence Group and Mandiant confirm a targeted campaign against government, financial, educational, legal, and professional services organizations in North America and Europe, deploying two novel malware families — WHIPSHOT and SLAPSHOT — for persistence and internal network tunneling.

Two critical vulnerabilities in Citrix NetScaler ADC and Gateway were exploited in the wild at least since September 1, 2026, three weeks before Citrix published its security bulletin on September 27. Google Threat Intelligence Group and Mandiant have confirmed a targeted attack campaign against government organizations, financial institutions, educational entities, law firms, and professional services companies in North America and Europe. Researchers identified two previously unseen malicious tools, dubbed WHIPSHOT and SLAPSHOT, designed to maintain persistence and tunnel traffic within victim internal networks.

The case raises immediate operational questions: Charles Carmakal, CTO of Mandiant Consulting, explicitly warned that applying patches without verifying pre-existing compromise leaves the attackers' presence intact. The recommendation inverts the standard "patch first, investigate later" instinct that has dominated perimeter device incident management for years.

Key Takeaways
  • Google and Mandiant confirm active exploitation of CVE-2026-88771 and CVE-2026-88772 at least since September 1, 2026, with delayed disclosure on September 27.
  • GreyNoise detected an exploit attempt on September 24 from IP address 149.104.78.141, three days before CVE-2026-88771 existed publicly.
  • Threat actors deployed two custom malware families: WHIPSHOT, a PHP web shell disguised as a Debian package, and SLAPSHOT, a Python tool for TCP tunneling with six built-in commands.
  • Targeted sectors include government, financial services, education, legal, and professional services in North America and Europe.

The Mechanism: DTLS Memory Overflow and Command Injection with Root Privileges

CVE-2026-88772 is a memory overflow in the DTLS (Datagram Transport Layer Security) protocol, enabled by default on NetScaler VPN virtual servers. Technical analysis by watchTowr documents that the NSPPE component copies an NSB string into a 35,840-byte scratch buffer without size verification. In a proof of concept, researchers filled the buffer with approximately 174 KB of data, demonstrating memory corruption. An assembly-level comparison shows the fix introduced by Citrix adds a bounds check absent in the vulnerable version.

CVE-2026-88771 instead allows unauthenticated remote command execution. The combination of the two flaws enables root-privileged access before the system even requests credentials. This attack profile — pre-authentication, remote, with elevated privileges — represents the most dangerous configuration for Internet-exposed devices.

Affected versions include 13.0-58.30, 12.1-65.21, 12.1-FIPS 12.1-55.297, and 13.1-42.47, according to Aviatrix analysis. Official release notes indicate fixed versions are 14.1-73.37 and later, and 13.1-64.23 and later, as reported by watchTowr.

WHIPSHOT and SLAPSHOT: The Architecture of Post-Exploitation Persistence

After initial compromise, attackers install WHIPSHOT, a PHP web shell that masquerades as a legitimate Debian package. The command-and-control channel hides Base64 payloads inside native HTTP headers, exploiting fields that standard network monitoring often fails to inspect closely. WHIPSHOT serves as a transport bridge for SLAPSHOT, a Python-written tool that establishes TCP tunnels through which operators route traffic to the victim's internal network.

SLAPSHOT supports six commands: open, push, pull, exch, close, ping. This structure enables not only selective data exfiltration but the construction of bidirectional channels for lateral movement. In at least one analyzed intrusion, attackers used the proxy for manual internal reconnaissance and credential theft, according to the Google/Mandiant advisory.

The design reflects precise operational logic: perimeter devices like NetScaler occupy a privileged position, often with full visibility into traffic between the Internet and the corporate network, and are rarely monitored with the same EDR tools applied to internal endpoints. A web shell on these systems effectively bypasses the entire security stack built to protect workstations and servers.

"Patching alone may not eradicate the threat actor from your environment" — Charles Carmakal, Mandiant Consulting CTO

The Hidden Timeline: When the Exploit Precedes the CVE

The campaign was not discovered through proactive research but during forensic investigations of already-compromised organizations. Benjamin Harris, founder and CEO of watchTowr, stated that "the vulnerabilities were discovered during incident response and forensic investigations at already-compromised organizations, meaning both the exploitation and Citrix's awareness preceded public disclosure."

GreyNoise provided independent evidence of this delay: on September 24, 2026, three days before CVE publication, GOG sensors detected an exploit attempt against CVE-2026-88771 originating from IP address 149.104.78.141. The organization retro-tagged the observation after deploying the CVE-2026-88771 tag on September 27, explicitly acknowledging that other indicators exist at higher TLP levels not published.

On Citrix's delay, Harris added: "Why Citrix took so long to disclose these vulnerabilities is a question only Citrix can answer." The company declined to comment on journalists' requests.

Immediate Actions

Operational recommendations derive directly from researcher analysis and the Google/Mandiant advisory:

  • Verify compromise before patching. Charles Carmakal explicitly recommended examining systems for signs of prior intrusion before applying updates, as patches do not remove already-installed web shells or persistent access.
  • Hunt for WHIPSHOT and SLAPSHOT indicators. The advisory identifies filenames, paths, and HTTP header patterns associated with the two tools; the search must focus on exposed NetScaler devices, not just internal endpoints.
  • Inspect VPN virtual servers with DTLS enabled. CVE-2026-88772 specifically targets this configuration, active by default: the attack surface is identifiable and bounded.
  • Analyze network traffic for anomalous TCP tunnels. SLAPSHOT generates connections that can appear as legitimate traffic; correlating suspicious HTTP sessions with TCP flows to internal destinations reveals the movement chain.

The Blind Spot of Perimeter Devices

The campaign reinforces an established pattern: sophisticated attackers target edge devices not for the intrinsic value of the systems, but for the architectural position they occupy. A compromised NetScaler is not the final victim — it is the bridge to everything it protects. The absence of equivalent EDR monitoring on these appliances, combined with operational teams' tendency to treat them as "secure by definition" infrastructure, creates a window of opportunity this campaign exploited for weeks.

The disclosure delay amplifies the systemic problem. When a vendor discovers vulnerabilities during incident response on already-hit customers, every day of silence extends exposure across the entire installed base. Citrix's history is not isolated in the industry, but the concentration of zero-days in recent years on NetScaler — with public exploits rapidly followed by mass campaigns — suggests this product's vulnerability management model requires structural revision, not just point patches.

The identity of the threat actors has not been determined. No infrastructure overlaps linking the campaign to known groups have emerged to date.

Information has been verified against cited sources and updated at time of publication.

Sources


Sources and references
  1. theregister.com
  2. vuink.com
  3. daily.dev
  4. aviatrix.ai
  5. news.lavx.hu
  6. bankinfosecurity.com
  7. greynoise.io
  8. labs.watchtowr.com