
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks.
Mandiant says the attacks began in at least early September and are believed to have impacted organizations in North America and Europe across the government, financial services, education, legal, and professional services sectors.
The campaign first came to light over the weekend, when Citrix administrators began reporting that IT suppliers, security teams, CERTs, and national cybersecurity agencies privately warned organizations about two unpatched NetScaler zero-days and, in some cases, advised them to shut down affected appliances.
Cybersecurity firm watchTowr later said it had verified reports that two NetScaler remote code execution zero-days were being exploited in the wild and that Citrix was preparing patches.
Citrix ultimately disclosed the flaws on Sunday as CVE-2026-88771 and CVE-2026-88772, with some researchers dubbing the vulnerabilities “PitScaler.”
Citrix confirmed that both had been exploited on unmitigated NetScaler deployments and releasing security updates to address them.
CVE-2026-88771 is an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments, while CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled.
Exploited in zero-day attacks
GreyNoise observed a threat actor attempting to exploit a Citrix NetScaler Gateway on September 24, three days before Citrix publicly disclosed CVE-2026-88771 and CVE-2026-88772.
According to GreyNoise, the attack originated from 149.104.78.141, and its platform detected it before CVE detections were available.
GreyNoise says the attacker attempted to modify /bin/sh to give a root shell and install a password-protected PHP web shell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver.
The attacker also attempted to modify /etc/httpd.conf so requests for what appeared to be CSS files, including receiver.min.css, would instead open the hidden PHP web shell.

Source: GreyNoise
The company is not publishing the full exploit for now, but recommends defenders hunt for the .ctxs.receiver file, related Alias or AliasMatch entries in httpd.conf, changes to the permissions of /bin/sh, and connections from the observed source IP.
A new Mandiant report provides more details about how CVE-2026-88772 is being exploited, confirming some of the same attack patterns seen by GreyNoise.
Mandiant says the exploits bypass authentication and cause the NetScaler Packet Processing Engine (NSPPE) to terminate unexpectedly, giving attackers root-level access.
“While Google Threat Intelligence Group does not possess exploit code, analysis of frontline telemetry suggests that transmitting specially malformed or fragmented record headers induces heap memory boundary corruption within the packet engine, diverting control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform,” explains Mandiant.
Google observed similar post-exploitation activity in intrusions, including attackers installing PHP web shells and modified the NetScaler web server configuration so non-executable file extensions would process them as PHP.
In one intrusion, Mandiant says the attackers modified /etc/httpd.conf so that .deb files would execute as PHP, allowing web shells to be used from directories normally holding NetScaler client software.
In other attacks, the threat actor used .sig files and modified the web server configuration so requests for .ico images under /vpn/media/ were instead mapped to malicious PHP files.
Google says this allowed malicious web shell requests to appear as requests for image files or CSS while executing attacker commands via the shell_exec() or eval() PHP functions.
Some of the web shells returned fake HTTP 404 responses when executing commands, further disguising the malicious activity.
Mandiant says the threat actors deployed two previously undocumented malware families, tracked as WHIPSHOT and SLAPSHOT.
WHIPSHOT is a PHP web shell disguised as a Debian package and stored in the NetScaler VPN scripts directory.
The malware acts as an HTTP proxy for SLAPSHOT, extracting Base64-encoded data from HTTP request headers and forwarding it to the tunneling malware running on a compromised device.
WHIPSHOT also checks whether SLAPSHOT is running and can extract and launch the embedded Python payloads in the background.
SLAPSHOT is a Python-based TCP tunneling tool that bridges the compromised NetScaler appliance and internal devices, allowing attackers to spread further into the network.
The malware accepts commands from WHIPSHOT and can open connections to internal hosts, send and receive data over those connections, and close sessions when finished.
Google says attackers used the proxy in at least one observed intrusion to manually conduct reconnaissance and steal credentials.
Mandiant says the malware can also terminate itself after periods of inactivity, making it harder to detect.
Although exploitation initially grants root privileges, commands executed by the web shells would normally run under a lower-privileged account that the NetScaler web servers run under.
To maintain root access, Google says the attackers modified permissions on /bin/sh so commands would run with elevated privileges.
“To establish persistent root-level execution for its web shells, the threat actor leveraged its lightweight installer web shells to assert the setuid (Set User ID) bit on the /bin/sh executable,” Mandiant says.
The threat actor also rebooted NetScaler appliances or restarted the web server to apply configuration changes.
NetScaler ADC and Gateway appliances are attractive targets because they are exposed to the Internet and often sit at the edge of internal networks, without having the same benefit of EDR software.
Mandiant says defenders should prioritize installing the latest Citrix security updates and inspect NetScaler appliances for signs of compromise.
Potential indicators include unauthorized PHP handlers or aliases in httpd.conf, suspicious .deb or .sig files containing PHP code, unusual HTTP 404 responses, unexpected NSPPE crashes, and the presence of /tmp/.uxdport or /tmp/.uxdlock files associated with SLAPSHOT.
Organizations should also check whether /bin/sh has been modified to run with setuid root permissions and look for suspicious Python processes launched with nohup or containing Base64-encoded payloads.
While Mandiant links this activity to CVE-2026-88772, Citrix says CVE-2026-88771 has also been exploited in attacks.
For organizations that cannot immediately patch, Mandiant recommends disabling DTLS where operationally feasible and blocking inbound UDP/443 upstream when DTLS is not required.
However, Google warns that these mitigations apply only to CVE-2026-88772 and do not protect against the separately exploited CVE-2026-88771 vulnerability.
Mandiant says installing the latest NetScaler security updates is the only way to address both flaws.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
