securityonline.info 1 Oct 2026, 08:13 UTC

Citrix NetScaler Zero Day Lets Attackers Seize Root Access Without Passwords

Citrix NetScaler Zero Day Lets Attackers Seize Root Access Without Passwords
CyberSIXT Evidence Panel Source marked as original reporting

ATTACKERS have been exploiting a Citrix NetScaler zero-day to seize root access on NetScaler ADC and Gateway devices without requiring a password, beginning at least in early September 2026. The issue, tracked as CVE-2026-88772, resides in NetScaler’s packet engine and appears triggered when malformed DTLS traffic is sent over UDP port 443 during the initial handshake.

GTIG and Mandiant say the exploitation likely corrupts heap memory, allowing the attacker to run code with root privileges and leave visible crash traces in logs. In several cases, actors then install hidden web shells and a proxy to reach internal networks, undermining network segmentation and increasing the risk of credential theft.

Mandiant’s findings describe web shells that masquerade as legitimate icon or image handling, including files disguised as .deb or .sig being executed as PHP, and web requests for harmless .ico icon files quietly invoking the shell. Two new tools were identified: WHIPSHOT, a PHP web shell hiding encoded commands in HTTP headers, and SLAPSHOT, a Python tunneller that can forward traffic into internal networks for reconnaissance and credential theft. Evidence points to a broader campaign with multiple victims and at least five sectors affected, though no formal attribution has been announced.

Citrix has issued fixes and notes that another zero-day, CVE-2026-88771, is also being exploited. Mitigations include upgrading to NetScaler 14.1-73.37 or 13.1-64.23 and later (with FIPS builds available), disabling DTLS and blocking inbound UDP/443 where feasible, inspecting web server PHP handlers, and rotating admin credentials and other secrets after patching. Organisations are advised to patch promptly and conduct post‑incident credential hygiene and forensic checks for exposed appliances.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline