Cyberattackers have been exploiting a previously unknown vulnerability in Citrix NetScaler appliances to gain root access, steal sensitive information, and spread malware within organizations. The attacks, which began at least by early September, have impacted companies across various sectors, including government, finance, education, law, and professional services, in North America and Europe.
The vulnerability, designated as CVE-2026-88772, is a memory overflow flaw that can lead to remote code execution or denial of service when the DTLS protocol is enabled. It’s one of two zero-day vulnerabilities discovered by cybersecurity firms, with the other (CVE-2026-88771) affecting all NetScaler ADC and Gateway deployments and allowing unauthenticated remote code execution.
Citrix has confirmed that both vulnerabilities have been exploited in real-world attacks and released security updates to address them. However, the damage may already be done, as some organizations have reported being compromised by attackers who deployed custom web shells and tunneling malware to gain a foothold within their internal networks.
The attack process involves exploiting the vulnerability to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform. This allows attackers to modify the NetScaler web server configuration, install PHP web shells, and use them to execute malicious commands while disguising the activity as legitimate requests for image files or CSS.
Google Threat Intelligence Group has analyzed frontline telemetry and confirmed that transmitting specially malformed or fragmented record headers induces heap memory boundary corruption within the packet engine, leading to control flow diversion and arbitrary shellcode execution. The group also observed post-exploitation activity, including attackers installing PHP web shells and modifying the NetScaler web server configuration to execute non-executable file extensions as PHP.
In some cases, the threat actors used fake HTTP 404 responses when executing commands to further disguise the malicious activity. Additionally, they deployed two previously undocumented malware families, tracked as WHIPSHOT and SLAPSHOT, with WHIPSHOT acting as an HTTP proxy for SLASHBOARD while extracting Base64-encoded data from HTTP requests.
The affected sectors include government institutions, financial services companies, educational institutions, law firms, and professional services organizations in North America and Europe. While Citrix has released security updates to address the vulnerabilities, it’s essential for these organizations to review their NetScaler deployments and ensure they have applied the necessary patches to prevent further exploitation.
As a practical takeaway for readers, cybersecurity professionals should be aware of the potential risks associated with unpatched NetScaler appliances and take proactive measures to mitigate them. This includes regularly updating software, monitoring network activity for suspicious behavior, and implementing robust security protocols to detect and respond to potential threats.
Source: Bleeping Computer — 2026-09-29