The vulnerability CVE-2026-88772 in Citrix NetScaler ADC and NetScaler Gateway is being actively exploited by unknown threat actors, who gain root-level access to targeted systems and deploy two new post-exploitation tools: WHIPSHOT and SLAPSHOT. The activity was detected in September 2026 by researchers at Mandiant Consulting and the Google Threat Intelligence Group (GTIG), targeting North America and Europe.

The attacks have hit organizations in critical sectors, including government agencies, financial institutions, technology companies, educational institutions, and legal/professional services. The breadth of targets suggests a well-organized threat actor with clear operational objectives, likely espionage or financial in nature. The speed of exploitation after the vulnerability was disclosed is a worrying sign for infrastructure managers.
According to The Hacker News, the CVE-2026-88772 exploit bypasses authentication and causes the NetScaler Packet Processing Engine (NSPPE), allowing initial root-level access. This means an attacker can gain complete control of the device without needing valid credentials, making the vulnerability extremely dangerous.
See also: CVE-2026-19490: The critical vulnerability in Citrix NetScaler
Technical Analysis of CVE-2026-88772 in NetScaler
CVE -2026-88772 has received a CVSS score of 9.5, classifying it as critical. As analyzed by watchTowr Labs, this is a memory overflow bug in the handling of the Datagram Transport Layer Security (DTLS) within the NSPPE. During the initial pre-authentication cryptographic handshake, the NSPPE parses inbound DTLS record structures. Sending specifically malformed or fragmented record headers causes heap memory boundary corruption within the packet engine, diverting control flow to execute arbitrary shellcode with root privileges on the underlying FreeBSD.

After successful exploitation, a web shell payload is automatically installed by modifying the target's httpd.conf files to handle Debian software package (.deb) format files as PHP scripts . This paves the way for the deployment of WHIPSHOT and SLAPSHOT . Changing this setting allows the attacker to place web shells with misleading file extensions in the /netscaler/gui/vpn/scripts/linux directory .
In other cases, the threat actor implemented a hidden configuration hook that disguises web shell execution as image requests and registers signature (.sig) files as executable PHP scripts after enabling the mod_php engine. The configuration also maps incoming HTTP requests, ending in .ico under /vpn/media/ , directly to a corresponding .sig with the same base name within /var/netscaler/gui/vpn/scripts/linux.
WHIPSHOT and SLAPSHOT: The New Exploit Tools CVE-2026-88772
WHIPSHOT is a lightweight PHP web shell that masquerades as a .deb or .sig file , offering instant command execution and automated persistence on the device. It extracts commands and payloads from HTTP headers, executes them, and returns the results. This technique allows attackers to hide Command-and-Control (C2) communications within normal HTTP headers, making them extremely difficult to detect by traditional detection systems.
See also: Citrix NetScaler RCE: Two new zero-day vulnerabilities in active exploitation
SLAPSHOT is a TCP tunneling tool written in Python that acts as an internal network bridge. It was designed to route traffic to internal networks for reconnaissance and credential theft . In at least one case observed by Google, the threat actor rerouted traffic through this proxy to perform manual internal reconnaissance and credential theft. The combination of the two tools creates a complete post-exploitation infrastructure that is difficult to detect.

The attack chain is completed by establishing persistent root-level execution for the web shells, leveraging the installer web shells to change the permissions of /bin/sh and then perform a full reboot of the NetScaler. This technique ensures that the malicious components survive even after reboots, making remediation particularly challenging.
See also: CVE-2026-53264: AI helped develop Linux root exploit
Impact and Protection from Vulnerability CVE-2026-88772
The vulnerability , CVE-2026-88772, directly affects organizations that use Citrix NetScaler ADC and NetScaler Gateway for secure remote access. In Europe, many government agencies and financial institutions rely on these devices, making the risk particularly high. Immediately applying available security updates is the first and most critical action that administrators should take.
In addition to applying patches, organizations should immediately check httpd.conf files for unauthorized modifications, look for suspicious .sig and .deb files in web server directories, and analyze log files for .ico requests with unusual response sizes or processing times.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
