Hackers Exploit Citrix NetScaler Zero-Day Vulnerabilities
Threat actors have been actively exploiting unpatched Citrix NetScaler zero-day vulnerabilities, deploying custom web shells, establishing tunneling malware, and gaining root access to spread across internal networks.

Active Exploitation of Citrix NetScaler Flaws
Cybersecurity firms report that attackers have exploited a Citrix NetScaler zero-day vulnerability to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. The campaign [first came to light over the weekend](https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/) when IT suppliers, security teams, CERTs, and national cybersecurity agencies privately warned organizations about two unpatched NetScaler zero-days, prompting some to shut down affected appliances.
Mandiant reports that the attacks began in at least early September, affecting organizations in North America and Europe. The targeted sectors include government, financial services, education, legal, and professional services. Following Administrator warnings, watchTowr verified that two remote code execution zero-days were actively exploited in the wild while Citrix prepared fixes. Citrix subsequently [disclosed the flaws](https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096) as CVE-2026-88771 and CVE-2026-88772, with some security researchers referring to the vulnerabilities under the moniker "PitScaler."
Vulnerability Details and Initial Discovery
Citrix confirmed that both vulnerabilities were exploited on unmitigated NetScaler deployments and released updates to address them. CVE-2026-88771 is an unauthenticated remote code execution flaw impacting all NetScaler ADC and Gateway deployments. Meanwhile, CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or a denial of service condition when DTLS is enabled.
Prior to the public disclosure by Citrix, [GreyNoise](https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation) observed a threat actor attempting to exploit a Citrix NetScaler Gateway on September 24. The platform detected the attack from the source IP address 149.104.78.141 before specific CVE signatures became available. The actor attempted to modify /bin/sh to grant a root shell and installed a password-protected PHP web shell within the NetScaler custom logon directories, while also altering httpd.conf to masquerade requests.
Attack Mechanics and Custom Malware Deployment
A detailed [Mandiant report](https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances?e=48754805) provides further insights into how CVE-2026-88772 is leveraged in real-world intrusions. The exploits bypass authentication and cause the NetScaler Packet Processing Engine (NSPPE) to terminate unexpectedly. Transmitting malformed or fragmented record headers induces heap memory boundary corruption within the packet engine, diverting control flow to execute arbitrary shellcode with root-level privileges on the underlying FreeBSD platform.
Intrusion analysis revealed that attackers deployed two undocumented malware families tracked as WHIPSHOT and SLAPSHOT. WHIPSHOT functions as a PHP web shell disguised as a Debian package or image file within VPN script directories, acting as an HTTP proxy for SLAPSHOT. SLAPSHOT is a Python-based TCP tunneling tool that bridges the compromised NetScaler appliance with internal network devices, facilitating lateral movement, reconnaissance, and credential theft.
Persistence Mechanisms and Mitigation Steps
To maintain persistent root access after initial exploitation, attackers modified the permissions on the /bin/sh executable by asserting the setuid bit using installer web shells. Attackers also rebooted NetScaler appliances or restarted web servers to apply configuration changes, and utilized fake HTTP 404 responses to obscure their command execution.
Because NetScaler ADC and Gateway appliances sit directly at the network edge without traditional endpoint detection and response (EDR) software protection, they remain attractive targets. Security agencies such as [CISA orders feds to patch exploited Citrix flaws by Wednesday](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/) have urged immediate remediation. Defenders are advised to install the latest Citrix security updates, inspect appliances for unauthorized PHP handlers in httpd.conf, check for modified /bin/sh permissions, and hunt for SLAPSHOT artifacts.
Sources
- BleepingComputerHackers exploit Citrix NetScaler zero-day to deploy web shells