Unknown hackers have exploited a newly patched security vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances to breach dozens of organizations across North America and Europe, according to findings published by Mandiant Consulting and Google Threat Intelligence Group in September 2026. The intrusions targeted government, financial services, technology, education, and legal and professional services sectors. Charles Carmakal, chief technology officer at Mandiant Consulting, warned of "broad and opportunistic exploitation" of the flaws by multiple threat actors in the near term.
The attackers weaponized CVE-2026-88772, a memory overflow bug with a CVSS score of 9.5, to bypass authentication and crash the NetScaler Packet Processing Engine, establishing root-level access on the underlying FreeBSD platform. Analysis of telemetry by Google indicates that specially malformed or fragmented DTLS record headers trigger heap memory corruption within the packet engine, redirecting control flow to execute arbitrary shellcode with root privileges. Following successful exploitation, attackers deployed a post-exploitation toolkit featuring previously unreported PHP web shells called WHIPSHOT, capable of hiding Base64-encoded command-and-control payloads inside native HTTP headers. The campaign also used a novel Python tunneler named SLAPSHOT, designed to proxy traffic into internal networks for reconnaissance and credential theft. Data from Censys shows 42,735 hosts and 323,527 web properties running NetScaler ADC or NetScaler Gateway as of September 28, 2026, with the United States accounting for 13,549 hosts, followed by Germany at 5,678 and the Netherlands, United Kingdom, and Switzerland at roughly 4% each.
The web shell payload self-installs by modifying target httpd.conf files to handle Debian software package format files as PHP scripts, enabling deployment of WHIPSHOT and SLAPSHOT. In some cases, the threat actor implemented a covert configuration hook that disguises web shell execution as image requests, registering signature files as executable PHP scripts after enabling the mod_php engine. "For example, clients accessing /vpn/media/e6ee7c85.ico would be served by the dropped PHP web shell e6ee7c85.sig," Google said. Web server access logs in at least one case showed GET requests returning HTTP 404 responses but exhibiting elevated processing durations and multi-kilobyte response sizes. GreyNoise began seeing additional malicious activity linked to CVE-2026-88771 starting September 28, 2026, around 8:30 a.m. EDT, followed by a significant surge the same day around 10:30 p.m. EDT, with the threat intelligence firm noting that what started as mass reconnaissance evolved into full-on mass exploitation across multiple independent actors and campaigns for botnet recruitment and access brokering.
The campaign highlights the continued targeting of edge devices to gain initial access to victim networks, according to Google's report. These appliances—including Application Delivery Controllers, VPN gateways, and firewalls—remain attractive targets because they're exposed to the internet, sit outside the reach of endpoint detection and response tools, and often store or process credentials that can be used to move deeper into the network. The lightweight PHP web shells offer direct command execution and automated appliance persistence, with SLAPSHOT removing its port and lock files and terminating its process if no active sessions or commands are received within 10 minutes to cover its tracks and minimize forensic traces. CERT-EU identified threat actors targeting NetScaler instances with Base64-encoded commands in the User-Agent string that modify configuration files to enable php_engine and deliver web shells in paths reachable from the internet. Organizations running NetScaler appliances face immediate risk from multiple threat actor groups deploying diverse toolsets against the same vulnerability, requiring urgent patching and forensic review of exposed systems. Edge infrastructure continues to represent a blind spot in enterprise security architecture, falling outside traditional monitoring perimeters while holding the keys to internal networks.

