A Critical Citrix Zero-Day Exploit Exposes Organizations to Web Shells and Malware
Citrix NetScaler appliances have been breached by hackers exploiting a zero-day vulnerability, allowing attackers to gain root access, steal credentials, and spread malware into internal networks. The attacks, which began in early September, have affected organizations across North America and Europe, including government agencies, financial institutions, educational institutions, law firms, and professional services.
The Citrix NetScaler CVE-2026-88772 zero-day vulnerability allows hackers to deploy custom web shells and tunneling malware, which can bypass authentication and grant root-level access. This is not the first time a critical Citrix vulnerability has been exploited; in 2019, hackers used a similar vulnerability to breach over 500 organizations worldwide.
GreyNoise, a cybersecurity firm, observed an attacker attempting to exploit a Citrix NetScaler Gateway on September 24, three days before Citrix publicly disclosed the vulnerability. The attack originated from a specific IP address and aimed to modify system files to install a password-protected PHP web shell. GreyNoise is not publishing the full exploit but recommends defenders hunt for specific files and configurations that may indicate an attacker has exploited this vulnerability.
Mandiant, another cybersecurity firm, has published a report detailing how the CVE-2026-88772 zero-day is being exploited. According to Mandiant, the attack bypasses authentication by causing the NetScaler Packet Processing Engine (NSPPE) to terminate unexpectedly, granting attackers root-level access. The exploit appears to induce heap memory boundary corruption within the packet engine, diverting control flow to execute arbitrary shellcode with root-level privileges.
The post-exploitation activity observed by Mandiant includes attackers installing PHP web shells and modifying the NetScaler web server configuration so non-executable file extensions would process them as PHP. In some cases, the threat actor used .deb files and modified the web server configuration to allow web shells to be executed from directories normally holding NetScaler client software.
The exploitation of this vulnerability has also led to the deployment of two previously undocumented malware families: WHIPSHOT and SLAPSHOT. WHIPSHOT is a PHP web shell disguised as a Debian package, stored in the NetScaler VPN scripts directory, which acts as an HTTP proxy for SLASHBOARD. This highlights the complexity and sophistication of modern cyber threats.
In light of this incident, it’s essential to take immediate action to protect against similar attacks. Organizations should ensure their Citrix appliances are patched with the latest security updates, monitor system files and configurations for signs of exploitation, and implement robust network segmentation and access controls to limit lateral movement in case of an attack. By taking these measures, organizations can significantly reduce their exposure to cyber threats and prevent devastating breaches like this one.
Source: Bleeping Computer — 2026-09-29