UNKNOWN threat actors have been observed exploiting a newly patched flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organisations in North America and Europe. The activity, detected by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has affected government, financial services, technology, education, and legal and professional services sectors.
Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine, enabling initial root‑level access on the NSPPE component running on FreeBSD. Google notes that specially malformed or fragmented DTLS records during the pre‑auth cryptographic handshake induce heap memory boundary corruption, allowing the attacker to execute arbitrary shellcode with root privileges.
Post‑exploitation payloads include PHP web shells such as WHIPSHOT, which exfiltrates commands via Base64‑encoded headers, and a Python tunneler named SLAPSHOT to proxy traffic for internal reconnaissance and credential theft. In some cases, attackers modify httpd[.]conf to treat .deb and .sig files as PHP scripts, enabling persistent web shells and further compromise. The campaigns also show covert hooks disguising web shell activity as image requests and unusual mappings that trigger execution.
GreyNoise reports additional activity linked to CVE-2026-88771 and 88772 beginning 28 September 2026, signalling mass exploitation and botnet‑style deployment aimed at bot recruitment and access brokering. Citrix warns edge devices remain attractive targets due to internet exposure and often lacking EDR coverage.