Mandiant and GTIG detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access.Mandiant and Google Threat Intelligence Group caught active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances in late September 2026. The bug, tracked as CVE-2026-88772 (CVSS score of 9.5), has been exploited in attacks in the wild since at least early September, hitting government, financial services, education, and legal services organizations across North America and Europe. Citrix disclosed a second zero-day being exploited alongside it, CVE-2026-88771.CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service, and it affects appliances with DTLS enabled. That’s particularly relevant for NetScaler Gateway because DTLS is enabled by default for VPN virtual servers unless an administrator has explicitly disabled it.The bug is triggered during the appliance’s first handshake, before any login is required. NetScaler’s packet engine processes incoming DTLS traffic to set up the encrypted connection. A specially crafted or fragmented header can corrupt its memory, allowing an attacker to run arbitrary code with root privileges on the underlying FreeBSD system, without needing any credentials.There are also signs of a successful attack in the logs. You may see an SSL handshake failure using DTLSv1.0 with the message “Handshake failure-Internal Error.” At the same time, the packet engine process crashes and the appliance’s watchdog fails to restart it. If these events happen close together, they could indicate that the exploit was successfully triggered.“While Google Threat Intelligence Group does not possess exploit code, analysis of frontline telemetry suggests that transmitting specially malformed or fragmented record headers induces heap memory boundary corruption within the packet engine, diverting control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform.” reads Google’s report. “Successful exploitation attempts generated two log artifacts:0-PPE-0 : default SSLLOG SSL_HANDSHAKE_FAILURE 0 : SPCBId - ClientIP - ClientPort - VserverServiceIP - VserverServicePort 443 - ClientVersion DTLSv1.0 - CipherSuite "TLS1-AES-256-CBC-SHA" - Session New - Reason "Handshake failure-Internal Error""Once inside, the attacker’s first move is installing a web shell, and the installation trick itself is worth appreciating for its pettiness. In some intrusions, the attacker edited the appliance’s Apache config to treat .deb files as executable PHP scripts, then dropped a web shell wearing that fake extension. Nobody expects a Debian package to run code, which is exactly the point.A stealthier version does the same trick with .sig files instead, and adds a redirect so that a request for a harmless looking .ico icon file actually gets served by the hidden PHP shell. Someone requesting /vpn/media/e6ee7c85.ico unknowingly triggers e6ee7c85.sig. Mandiant even noticed some of these requests returning a normal-looking 404 error while taking unusually long to process, which is the kind of detail that only stands out once you know to look for it.Getting root access the first time is easy because the exploit already runs with root privileges. To keep that access for future web requests, the installer makes /bin/sh setuid, so commands run through the shell continue to run as root.It then forces a full reboot of the appliance to make sure the changes stay in place. Simple, effective, and a pretty clever way to make the compromised system keep giving the attacker root access.The two custom tools doing the real work are called WHIPSHOT and SLAPSHOT, and Mandiant hadn’t seen either before. “Following successful exploitation, the initial web shell payload self-installs by modifying target httpd.conf files, configuring the system to treat specified non-script file types as executable PHP scripts, setting the stage for the deployment of additional custom malware including WHIPSHOT (a PHP web shell) and SLAPSHOT (a Python proxy/tunneler).” states the report.WHIPSHOT is the PHP web shell, disguised as a Debian package, that reads commands hidden inside sequential HTTP header fields, decodes them from Base64, and forwards them over a local loopback connection. It also quietly kills its own error reporting and always answers with a 404, so a scan of the web server logs shows nothing unusual on the surface.SLAPSHOT is what lets the attacker move beyond the compromised appliance. It creates a simple Python proxy that opens a local port and forwards TCP traffic into the internal network.In one confirmed attack, the attacker used it to explore the network and look for credentials. The connection started from an internet-facing gateway, giving the attacker a tunnel into the internal network.SLAPSHOT even cleans up after itself if nobody’s using it, closing idle sessions after 15 minutes and shutting itself down entirely after 10 minutes with no activity, deleting its own port and lock files on the way out. That’s not laziness, that’s someone who’s thought about what a forensic analyst would go looking for and decided not to leave it lying around.This is not a new problem. Edge devices such as VPN gateways, load balancers and firewalls are often targeted because they are exposed to the internet, are usually outside standard endpoint security tools, and may contain credentials that provide access to the internal network.Mandiant recommends patching to the fixed versions first. Isolating a remote-access gateway can cause major disruption. If patching is not immediately possible, disabling DTLS and blocking inbound UDP/443 can stop this specific attack path, but it does not protect against the second zero-day.If an appliance may have been compromised, assume that all credentials it handled are exposed. This includes admin accounts, SSH keys, TLS certificates, LDAP and RADIUS credentials, and other secrets used to access internal systems. Rotate them after the appliance has been patched, not before.“This campaign underscores the continued targeting of edge devices to gain initial access to victim networks, a trend that GTIG has tracked across a range of threat actors. Notably, these vulnerabilities made up about half of the enterprise-related zero-days in 2025.” contludes the report.Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, Citrix NetScaler)