Attackers exploited two unreported vulnerabilities in Citrix NetScaler ADC and Gateway appliances to execute remote commands and install backdoors and tunneling tools that enabled access to internal networks. According to Mandiant, the attacks began in early September 2026 and targeted organizations in North America and Europe across the government, financial, education, legal, and professional services sectors.
Citrix disclosed the two vulnerabilities on September 27 and released security updates to address them. The first, CVE-2026-88771, is an unauthenticated remote code execution vulnerability affecting all NetScaler ADC and Gateway deployments. CVE-2026-88772 is a memory overflow vulnerability that may lead to remote code execution or denial of service when DTLS is enabled. The company confirmed that both vulnerabilities were exploited in environments that had not yet been patched.
How Were the Appliances Exploited?
GreyNoise observed an exploitation attempt on September 24, three days before the public disclosure. The attacker attempted to modify /bin/sh to grant elevated shell privileges, planted a password-protected PHP backdoor within a NetScaler path, and then modified web server settings so that requests appearing to be CSS files would execute the malicious code.
Mandiant confirmed that the exploitation bypasses authentication and causes the NSPPE packet-processing engine to crash, granting the attacker root-level access to the underlying FreeBSD system. It also observed modifications that caused extensions such as .deb and .sig to be processed as PHP files, making backdoor requests appear to be requests for images or static files, and sometimes returning fake 404 responses to conceal the activity.
Intrusion Tools and Lateral Movement
Mandiant identified two previously undocumented malware families, WHIPSHOT and SLAPSHOT. WHIPSHOT operates as a PHP backdoor disguised as a Debian package and is used as a proxy for SLAPSHOT, a TCP tunneling tool written in Python. This architecture allows connections to be opened with internal hosts and data to be sent and received, supporting reconnaissance, credential theft, and propagation within the network.
To maintain root privileges, the attackers modified the permissions of /bin/sh to enable the setuid bit. They also rebooted the appliances or the web server to apply the modifications, and self-termination mechanisms were used after periods of inactivity to reduce the chances of discovery.
What Should Defenders Check?
- Install the latest Citrix security updates and scan the appliances for indicators of compromise.
- Review unauthorized additions or rules in httpd.conf, and search for .deb or .sig files containing PHP code.
- Check for NSPPE crashes, unusual 404 responses, and the presence of the files /tmp/.uxdport or /tmp/.uxdlock.
- Inspect the permissions of /bin/sh and Python processes launched through nohup or containing Base64 payloads.
If updating immediately is not possible, Mandiant recommends disabling DTLS where feasible and blocking inbound UDP/443 when the service is not required. However, this measure mitigates only the risks of CVE-2026-88772 and does not protect against CVE-2026-88771; therefore, installing NetScaler updates remains the only remediation that covers both vulnerabilities.
Why Does This Matter?
The campaign combines code execution, persistence with elevated privileges, and concealment of backdoors within seemingly ordinary files and settings, then uses the edge appliance as a pivot point into the internal network. Its practical danger lies in the fact that NetScaler appliances are exposed to the internet and sit at network boundaries, and often do not have the same endpoint monitoring capabilities available on internal servers. Therefore, applying the update alone is not enough; a forensic investigation for traces of prior compromise should also be conducted.