Active intrusions exploiting the Citrix NetScaler CVE-2026-88772 zero-day deployed tailored web shells and tunneling implants to obtain root control, harvest credentials, and move into connected internal networks. Mandiant places the start of the activity in at least early September, with affected entities in North America and Europe spanning government, financial services, education, legal, and professional services. Citrix disclosed the issues on Sunday as CVE-2026-88771 and CVE-2026-88772, a pair some researchers call "PitScaler," confirmed exploitation on unmitigated NetScaler deployments, and issued security updates.
Affected products and flaws
CVE-2026-88771 is described as an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments. CVE-2026-88772 is described as a memory overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled.
Vulnerability data lists affected builds as ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service, detailed in NVD CVE-2026-88772. The same research notes CVSS 4.0: 9.5 CRITICAL ( AV:N/AC:H/PR:N/UI:N with high confidentiality, integrity and availability impact.
Citrix CTX697096, covering CVE-2026-88771 through 88778, states active exploitation of 88771 and 88772 on unmitigated appliances. Prior August builds 14.1-73.32 and 13.1-63.21 do not fix this issue. Exploitation requires DTLS to be enabled; on Gateway, DTLS is on by default for VPN virtual servers unless an administrator set -dtls OFF. DTLS-type vServers are also in scope.
CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog, noting both are critical zero-day vulnerabilities that can independently enable remote code execution and that threat actors are actively exploiting these vulnerabilities globally, per CISA alert.
The episode surfaced over the weekend when Citrix administrators reported private warnings from IT suppliers, security teams, CERTs, and national cybersecurity agencies about two unpatched NetScaler zero-days, with shutdown of affected appliances advised in some cases. watchTowr said it had verified reports that two NetScaler remote code execution zero-days were being exploited in the wild and that Citrix was preparing patches.
How the attack works
GreyNoise saw an attempt against a Citrix NetScaler Gateway on September 24, three days before Citrix publicly disclosed CVE-2026-88771 and CVE-2026-88772. The attempt came from 149.104.78.141, and the company said its platform caught it before CVE detections were available.
In that attempt the actor tried to alter /bin/sh to provide a root shell and to drop a password-protected PHP web shell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver. The actor also tried to edit /etc/httpd.conf so requests that looked like CSS files, including receiver.min.css, would instead launch the concealed PHP web shell. GreyNoise said it is not publishing the full exploit for now, and urged hunts for the .ctxs.receiver file, related Alias or AliasMatch entries in httpd.conf, permission changes to /bin/sh, and connections from the observed source IP.
Mandiant analysis of CVE-2026-88772 reports unauthenticated exploitation that makes the NetScaler Packet Processing Engine (NSPPE) terminate unexpectedly and yields root-level access. Frontline telemetry, as characterized by Google Threat Intelligence Group, points to malformed or fragmented record headers causing heap boundary corruption inside the packet engine and redirection to attacker shellcode with root operating-system rights on the underlying FreeBSD platform.
Post-exploitation centered on concealing PHP shells inside the web server configuration. Google observed PHP web shells installed alongside NetScaler web server changes so non-executable extensions would be handled as PHP. In one intrusion, /etc/httpd.conf was changed so .deb files would execute as PHP, permitting shell use from directories that normally store NetScaler client software. In other intrusions the actor used .sig files and remapped requests for .ico images under /vpn/media/ to malicious PHP files. That let shell requests masquerade as image or CSS fetches while running attacker commands through the PHP shell_exec() or eval() functions. Some shells answered with fake HTTP 404 responses during command execution.
Two previously undocumented families were deployed, tracked as WHIPSHOT and SLAPSHOT. WHIPSHOT is a PHP web shell disguised as a Debian package and stored in the NetScaler VPN scripts directory. It serves as an HTTP proxy for SLAPSHOT, pulling Base64-encoded data from HTTP request headers and passing it to the tunneling malware on the compromised device. WHIPSHOT also checks whether SLAPSHOT is running and can extract and launch the embedded Python payloads in the background.
SLAPSHOT is a Python-based TCP tunneling tool that bridges the compromised NetScaler appliance and internal devices, enabling further spread into the network. It takes commands from WHIPSHOT and can open connections to internal hosts, send and receive data over those connections, and close sessions when finished. Attackers used the proxy in at least one observed intrusion to manually conduct reconnaissance and steal credentials. The malware can also terminate itself after periods of inactivity.
Although initial exploitation yields root privileges, commands run through the web shells would ordinarily execute as a lower-privileged account used by the NetScaler web servers. To keep root execution, the actor used lightweight installer shells to set the setuid bit on the /bin/sh executable. The actor also rebooted NetScaler appliances or restarted the web server to apply configuration changes. NetScaler ADC and Gateway appliances are attractive because they face the Internet and often sit at the edge of internal networks without the same benefit of EDR software.
Proof of concept
A Python 3 check-only PoC for CVE-2026-88772 covering Citrix NetScaler ADC and NetScaler Gateway is published at CVE-2026-88772 GitHub PoC, with catalog pages at PoC detail and PoC catalog.
The PoC fingerprints Gateway/ADC login surfaces, parses build strings when exposed, checks UDP/443, and optionally sends a benign DTLS ClientHello probe. It does not include the memory overflow trigger seen weaponized in the wild.
pip install -r requirements.txt
python poc.py -u https://vpn.example.com --mode check
python poc.py -u https://vpn.example.com --mode check --dtls-probe
python poc.py -u https://vpn.example.com --build 14.1-73.32 --mode check
python poc.py --list targets.example.txt --mode check -j 12
The project notes describe it as detection plus safe DTLS probe with no overflow packet, for authorized testing and incident response only, warning against crashing production appliances.
Detection and mitigation
Mandiant urges installing the latest Citrix security updates and inspecting NetScaler appliances for compromise. While Mandiant links this activity to CVE-2026-88772, Citrix says CVE-2026-88771 has also been exploited in attacks.
Look for unauthorized PHP handlers or aliases in httpd.conf, suspicious .deb or .sig files containing PHP code, unusual HTTP 404 responses, unexpected NSPPE crashes, and the presence of /tmp/.uxdport or /tmp/.uxdlock files associated with SLAPSHOT. Check whether /bin/sh has been modified to run with setuid root permissions and look for suspicious Python processes launched with nohup or containing Base64-encoded payloads.
For organizations that cannot immediately patch, Mandiant recommends disabling DTLS where operationally feasible and blocking inbound UDP/443 upstream when DTLS is not required. Google warns those mitigations apply only to CVE-2026-88772 and do not protect against the separately exploited CVE-2026-88771 vulnerability. Installing the latest NetScaler security updates is described as the only way to address both flaws.
Further context is available in NVD record, shutdown warning report, CISA deadline report, auth bypass attacks, RCE exploitation order, and patch urgency notice.