Nora
Blake

Citrix NetScaler CVE-2026-88772 Exploitation: Web Shells, Root Access and Internal Tunneling

Nora Blake

Sep 30, 2026

7 min read

Citrix NetScaler CVE-2026-88772 Exploitation Web Shells Root Access and Internal Tunneling

TL;DR

Attackers exploited Citrix NetScaler CVE-2026-88772 to gain root-level execution, establish persistence, and tunnel into internal networks.

  • Successful attacks deployed web shells and used WHIPSHOT and SLAPSHOT for internal proxying, reconnaissance, and credential theft.
  • Organizations should install Citrix’s fixed builds, then investigate affected appliances and internal systems for post-exploitation activity.
  • Hexnode XDR provides downstream threat hunting and device containment for connected Windows and macOS endpoints, but cannot inspect, patch, or clean the NetScaler appliance itself.

Citrix NetScaler CVE-2026-88772 has moved beyond a critical vulnerability disclosure into a documented post-exploitation campaign.

Mandiant and Google Threat Intelligence Group (GTIG) identified active exploitation affecting NetScaler ADC and NetScaler Gateway appliances. Evidence suggests the campaign has operated since at least early September 2026.

Affected organizations were located in North America and Europe. They spanned government, financial services, technology, education, legal and professional services.

The attack chain is particularly significant because exploitation occurs before authentication and can provide root-level execution on the NetScaler appliance. In observed intrusions, attackers subsequently established persistence by modifying web server configurations, deploying web shells, and altering /bin/sh permissions. Mandiant also observed attackers using compromised appliances to proxy traffic into internal networks.

CVE-2026-88772 is a critical memory-overflow vulnerability in NetScaler ADC and NetScaler Gateway that can cause remote code execution or denial of service when DTLS is enabled. Citrix assigned the vulnerability a CVSS v4.0 score of 9.5 and confirmed exploitation in the wild.

Citrix NetScaler CVE-2026-88772 at a Glance

Vulnerability Attribute  Information 
CVE  CVE-2026-88772 
Affected products  NetScaler ADC and NetScaler Gateway 
Vulnerability type  Memory overflow / CWE-119 
CVSS  9.5, Critical, CVSS v4.0 
Attack prerequisite  DTLS enabled; DTLS is enabled by default on VPN vServers 
Potential impact  Remote code execution or denial of service 
Observed execution context  Root-level access in documented exploitation 
Exploitation status  Confirmed active exploitation 
Fixed NetScaler ADC/Gateway builds  14.1-73.37 and 13.1-64.23 or later 
Fixed FIPS/NDcPP builds  14.1-73.37 FIPS and 13.1-37.279 FIPS/NDcPP or later 
CISA KEV  Added September 27, 2026 

CVE-2026-88772 requires DTLS to be enabled, according to Citrix. NetScaler Gateway VPN virtual servers enable DTLS by default unless administrators explicitly disable it.

How Malformed DTLS Traffic Reaches Root on NetScaler

The available evidence provides a clearer picture of how Citrix NetScaler CVE-2026-88772 reaches code execution.

During the pre-authentication cryptographic handshake, the NetScaler Packet Processing Engine, or NSPPE, parses incoming DTLS record structures.

GTIG does not possess the exploit code. However, its analysis of frontline telemetry suggests specially malformed or fragmented DTLS record headers can trigger heap memory boundary corruption inside NSPPE. The corruption can divert execution to attacker-supplied shellcode with root-level privileges on the underlying FreeBSD platform.

Successful exploitation attempts also produced observable artifacts. These included DTLS handshake failures and messages showing unexpected NSPPE process termination.

This distinction matters. Citrix describes the vulnerability broadly as a memory overflow leading to RCE or denial of service. Mandiant and GTIG’s incident-response evidence provides the more detailed explanation of how exploitation appears to work in observed environments.

Attackers Turned Web Server Configuration Into Persistence

After gaining root-level execution, attackers established additional persistence on the appliance.

Mandiant found attackers modifying NetScaler httpd.conf files so extensions that would not normally indicate PHP code could execute as PHP scripts.

Observed examples included files masquerading as Debian packages, signature files and other web assets. Some web shells returned fake HTTP 404 Not Found responses while processing encoded attacker commands.

The attackers also addressed a privilege problem created after initial exploitation.

Initial exploitation executes with root privileges. However, subsequent requests handled by the web server run under an unprivileged service context. Mandiant observed attackers setting the setuid bit on /bin/sh using chmod u+s /bin/sh. This allowed subsequent web-shell commands to execute with elevated permissions.

Attackers also restarted the web server or rebooted the NetScaler appliance to activate configuration changes. Organizations should investigate previously exposed appliances for persistence even after applying the security update.

WHIPSHOT and SLAPSHOT Turn NetScaler Into an Internal Proxy

Mandiant identified two previously undocumented malware families in the campaign: WHIPSHOT and SLAPSHOT.

WHIPSHOT is a PHP web shell disguised as a Debian package. It accepts encoded data through HTTP request headers and acts as the external transport layer for SLAPSHOT.

WHIPSHOT communicates locally with SLAPSHOT through the loopback interface. It can also launch the Python payload if the tunneler is not already running.

SLAPSHOT provides the TCP tunneling layer used to reach internal hosts.

The Python-based tunneler can establish arbitrary TCP connections to target hosts and relay traffic through the compromised NetScaler appliance. Its command protocol supports opening connections, transmitting data, receiving data and closing sessions.

More importantly, this was not only a theoretical malware capability. In at least one observed intrusion, Mandiant saw the threat actor route traffic through the proxy to conduct internal reconnaissance and credential theft.

That activity changes the incident-response boundary. Defenders should not limit investigation to the compromised NetScaler appliance when evidence indicates attackers may have used it as a path toward internal systems.

Patch CVE-2026-88772, Then Hunt for Existing Persistence

Citrix confirmed exploitation of both CVE-2026-88772 and CVE-2026-88771 on unmitigated NetScaler deployments. CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on September 27.

For CVE-2026-88772, organizations should first determine whether DTLS is enabled. According to Citrix, the vulnerability affects NetScaler ADC or NetScaler Gateway when DTLS is enabled. NetScaler Gateway VPN virtual servers enable DTLS by default unless administrators explicitly disable it.

Citrix recommends installing the relevant fixed build:

  • NetScaler ADC and Gateway 14.1-73.37 or later
  • NetScaler ADC and Gateway 13.1-64.23 or later
  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS or later
  • NetScaler ADC 13.1-FIPS/NDcPP 13.1-37.279 or later

Mandiant likewise recommends prioritizing the latest Citrix build. However, organizations should investigate for compromise rather than treating patch installation as post-incident remediation by itself.

Investigators should review the appliance for altered web server configuration, unexpected executable PHP handlers, suspicious web shells and unauthorized setuid permissions on /bin/sh. Mandiant also recommends extending hunting across broader infrastructure for potential activity originating from compromised NetScaler systems.

Thumbnail-For-XDR-Intro-Deck

Introduction to Hexnode XDR

See how Hexnode XDR brings endpoint threat visibility, investigation, and response capabilities into a unified security workflow.

Download the Presentation

Investigating Downstream Endpoint Activity With Hexnode XDR

Hexnode XDR does not replace the Citrix security update or appliance-level investigation. It should also not be positioned as detecting CVE-2026-88772 exploitation on NetScaler.

Its relevance begins downstream.

Mandiant observed compromised NetScaler appliances being used to proxy traffic into internal networks. SLAPSHOT provided the TCP tunneling layer that allowed attackers to connect to internal hosts through the compromised appliance. In at least one intrusion, attackers used this proxy path for internal reconnaissance and credential theft.

This activity gives security teams a reason to investigate managed endpoints reachable from the affected environment. Hexnode XDR provides security visibility across supported Windows and macOS endpoints. Security teams can use endpoint telemetry and query-based Threat Hunt capabilities to investigate suspicious downstream activity.

Where investigation identifies a compromised endpoint, the response actions include:

  • Isolate Device to restrict endpoint network access.
  • Kill Process to terminate an identified malicious process.
  • Quarantine File to contain an identified threat file.
  • Delete File to remove an identified malicious file.

Security teams can separately use Threat Hunt and its query engine for broader endpoint investigation.

These controls operate on managed endpoints. They do not inspect, clean, patch or remediate the NetScaler appliance itself.

What to Do After CVE-2026-88772 Exposure

Organizations running affected NetScaler deployments should prioritize four actions:

  1. Identify affected NetScaler configurations. Determine whether deployed versions are vulnerable and whether DTLS is enabled for CVE-2026-88772 exposure.
  2. Install Citrix’s fixed builds. Apply the appropriate 14.1, 13.1 or FIPS/NDcPP update without unnecessary delay.
  3. Hunt the appliance for post-exploitation artifacts. Review web server configuration, web shells, suspicious file handlers and /bin/sh permissions.
  4. Expand investigation beyond NetScaler when compromise is suspected. Review internal systems for activity consistent with reconnaissance, credential access or subsequent attacker movement.

The campaign shows that an edge-device compromise can extend beyond the affected appliance and expose internal systems to further attacker activity.

Conclusion

Citrix NetScaler CVE-2026-88772 gave attackers more than an opportunity to crash an exposed service.

Mandiant documented a chain from pre-authentication DTLS processing to root-level execution, persistent PHP web shells and an internal tunneling architecture built around WHIPSHOT and SLAPSHOT. Attackers used that infrastructure for internal reconnaissance and credential theft in at least one observed intrusion.

Updating affected NetScaler appliances addresses CVE-2026-88772, while suspected compromises require further investigation.

For those downstream endpoints, endpoint investigation and containment can complement the appliance-focused response. They do not substitute for Citrix’s patches or NetScaler-specific forensic investigation.

Share

Nora Blake

I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.