SecPod

Learn Search

Search across all Learn content

← Back to Security Research
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026By Yash Raj

Summary

Mandiant and Google Threat Intelligence Group (GTIG) observed active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances. The flaw, CVE-2026-88772 , is a pre-authentication memory overflow in DTLS handling that gives an attacker root-level code execution on the underlying FreeBSD system. A second zero-day, CVE-2026-88771, was exploited alongside it.

After exploitation, the actors deploy two previously unseen custom tools: WHIPSHOT , a PHP web shell disguised as a Debian package, and SLAPSHOT , a Python proxy that tunnels traffic from the gateway into the internal network. Together they provide stealthy command execution, persistent root access, and a path toward internal credentials.

Background

GTIG and Mandiant identified the activity in late September 2026, with exploitation traced back to at least early September. Victims span government, financial services, education, and legal services organizations in North America and Europe.

The campaign fits a broader pattern of attackers targeting edge devices such as VPN gateways, load balancers, and firewalls. These systems are internet-facing, usually sit outside standard endpoint security tooling, and may hold credentials that open the internal network. GTIG reports that such flaws made up roughly half of enterprise-related zero-days in 2025. DTLS is enabled by default on NetScaler Gateway VPN virtual servers unless an administrator disables it, which widens exposure for CVE-2026-88772.

Vulnerability Details

CVE IDCVSS ScoreEPSS ScoreAffected Products
CVE-2026-88772 9.5 (Critical)1.30%NetScaler ADC and Gateway 14.1 prior to 14.1-73.37; 13.1 prior to 13.1-64.23; NetScaler ADC FIPS prior to 14.1-73.37 FIPS; NetScaler ADC FIPS and NDcPP prior to 13.1-37.279.
CVE-2026-88771 9.5 (Critical)1.06%NetScaler ADC and Gateway 14.1 prior to 14.1-73.37; 13.1 prior to 13.1-64.23; NetScaler ADC FIPS prior to 14.1-73.37 FIPS; NetScaler ADC FIPS and NDcPP prior to 13.1-37.279.

Attack Methodology

  1. 1. Pre-authentication exploitation. The attacker sends a crafted or fragmented DTLS record header during the first handshake. The malformed header corrupts heap memory in the packet engine and diverts control flow to shellcode running as root on FreeBSD, with no credentials needed.
  2. 2. Web shell self-installation. The initial payload edits the appliance's httpd.conf so that non-script file types execute as PHP. Some intrusions used .deb files; a stealthier variant used .sig files plus a redirect so a request for an .ico icon is served by the hidden PHP shell.
  3. 3. Root persistence. The installer sets the setuid bit on /bin/sh so commands issued through the web shell keep running as root, then forces a full appliance reboot so the changes survive.
  4. 4. WHIPSHOT command channel. The PHP web shell, disguised as a Debian package, reads Base64-encoded commands from sequential HTTP header fields and relays them over a local loopback connection. It suppresses its own error reporting and always answers with a 404.
  5. 5. SLAPSHOT tunneling. A Python proxy opens a local port and forwards TCP traffic into the internal network. It closes idle sessions after 15 minutes, exits after 10 minutes without activity, and removes its port and lock files on shutdown.
  6. 6. Internal exploration. In one confirmed intrusion, the actor used the tunnel from an internet-facing gateway to explore the internal network and search for credentials.

Indicators of Compromise (IOCs)

● Request path:  /vpn/media/e6ee7c85.ico  (served by  e6ee7c85.sig)

● Modified httpd.conf entries mapping .deb or .sig files to PHP execution, plus a redirect from an  .ico request to a  .sig file

● Web requests returning a normal-looking 404 with unusually long processing time

● /bin/sh with the setuid bit set, followed by an unplanned appliance reboot

● Local proxy port and lock files created by SLAPSHOT, removed after 10 minutes of inactivity

MITRE ATT&CK Mapping

Technique IDTechnique NameTactic
T1190 Exploit Public-Facing Application Initial Access
T1505.003 Server Software Component: Web Shell Persistence
T1548.001 Abuse Elevation Control Mechanism: Setuid and Setgid Privilege Escalation
T1036.008 Masquerading: Masquerade File Type Defense Evasion
T1070.004 Indicator Removal: File Deletion Defense Evasion

Visual Attack Flow

Mitigation

  1. 1. Patch first. Upgrade NetScaler ADC and Gateway to 14.1-73.37 or later, or 13.1-64.23 or later; NetScaler ADC FIPS to 14.1-73.37 FIPS or later; NetScaler ADC FIPS and NDcPP to 13.1-37.279 or later. Both CVEs share these fixed builds (Citrix advisory CTX697096).
  2. 2. Apply the interim DTLS control only if patching is delayed. Disable DTLS and block inbound UDP/443 to close the CVE-2026-88772 path. This does not cover CVE-2026-88771.
  3. 3. Audit web server configuration and content. Review httpd.conf for .deb or .sig files handled as PHP, inspect /vpn/media/ , and flag slow 404 responses.
  4. 4. Check privilege state. Verify /bin/sh does not carry the setuid bit and investigate unexplained appliance reboots.
  5. 5. Watch for tunneled internal activity. Review traffic that originates from the gateway toward internal hosts, since SLAPSHOT forwards TCP from a local port on the appliance.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026

Open Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited
Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

CVE Research

Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

Citrix has released security updates for NetScaler ADC and NetScaler Gateway addressing CVE-2026-88771 and CVE-2026-88772, two critical remote code execution vulnerabilities. Exploits against unmitigated deployments have been observed. CVE-2026-88771 affects all deployments, including default configurations; CVE-2026-88772 applies when DTLS is enabled, including the default state on VPN virtual servers. This article covers impact, affected and fixed versions, how to confirm exposure, and recommended remediation.

Sep 28, 2026