securityaffairs.com 30 Sept 2026, 07:25 UTC

Citrix NetScaler Zero Day Gives Attackers Tunnels Into Internal Networks

Citrix NetScaler Zero Day Gives Attackers Tunnels Into Internal Networks
CyberSIXT Evidence Panel Source marked as original reporting

MANDIANT and Google Threat Intelligence Group (GTIG) have detailed active exploitation of a Citrix NetScaler zero-day affecting the NetScaler ADC and Gateway appliances, tracked as CVE-2026-88772 (with a CVSS of 9.5) and CVE-2026-88771. The campaigns, observed from late September 2026, target devices with DTLS enabled and can yield remote code execution or denial of service during the first handshake, before any login. The activity has impacted organisations across North America and Europe, including government, financial services, education and legal sectors.

The attackers install two bespoke tools, WHIPSHOT and SLAPSHOT. WHIPSHOT is a PHP web shell disguised as a Debian package, reading commands hidden in HTTP headers, Base64-decoding them, and sending them via a loopback, while suppressing error output and returning 404s to avoid obvious logs. SLAPSHOT is a Python proxy that creates a local port to forward traffic into the internal network, enabling lateral access.

In one confirmed case, SLAPSHOT was used to map credentials within the network; the chain begins with an internet-facing gateway, giving the intruder a tunnel into the internal environment. SLAPSHOT also self-cleans after inactivity. Mandiant recommends patching to fixed versions immediately; if patching is delayed, disable DTLS and block inbound UDP/443 on remote-access gateways. If a device is compromised, rotate all credentials and secrets after patching.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline