Morning Edition · №
Technology · Cybersecurity SAN FRANCISCO

Hackers Exploit Citrix NetScaler Zero-Days to Plant Root-Level Web Shells

Mandiant and Google researchers say attackers used two custom tools, nicknamed WHIPSHOT and SLAPSHOT, to seize root access on unpatched appliances at government agencies, banks and universities.

Hackers Exploit Citrix NetScaler Zero-Days to Plant Root-Level Web Shells
A server rack similar to the network appliances targeted in the Citrix NetScaler attacks (file photo, not the actual devices affected). — Photograph: Tyler / Unsplash
SHARE X f in ⧉

Hackers are breaking into Citrix NetScaler appliances at government agencies, banks, universities and law firms across North America and Europe, using a pair of previously unknown flaws to seize root-level control and plant two custom hacking tools researchers had never seen before.

Citrix disclosed the two vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, on September 27 and released patches the same day. Both carry a CVSS severity score of 9.5. CVE-2026-88771 lets an attacker execute code on a vulnerable NetScaler ADC or Gateway appliance in its default configuration; CVE-2026-88772 is a memory-overflow bug, triggered by malformed encrypted handshake data, that corrupts the appliance's packet-processing engine and hands an attacker root access on the underlying operating system. The U.S. Cybersecurity and Infrastructure Security Agency added both to its Known Exploited Vulnerabilities catalog the day they were disclosed.

Two New Tools, Built to Hide

Mandiant and Google's Threat Intelligence Group, which found the campaign, say attackers began exploiting the flaws as early as September 24 — three days before Citrix told the public — and that activity surged into what the threat-intelligence firm GreyNoise described as mass exploitation by multiple, apparently unrelated attackers. Once inside, intruders installed a web shell the researchers named WHIPSHOT, a program disguised as an ordinary Debian software package that hides commands inside HTTP headers, and a companion tool called SLAPSHOT, which tunnels traffic to other machines on the victim's internal network and erases its own traces after roughly ten minutes of inactivity.

The intrusions gave attackers a foothold to explore victims' internal networks and harvest credentials, according to Google's threat-intelligence writeup, though the companies have not said how many organizations were ultimately compromised beyond describing victims in government, financial services, education and professional-services sectors.

Security researchers were also frustrated by how long the flaws went undisclosed. "Why Citrix took so long to disclose these vulnerabilities is a question only Citrix can answer," said Benjamin Harris, chief executive of the security firm watchTowr, in comments reported by The Register.

"NetScaler customers should prioritize examining systems for compromise before upgrading/patching."

Charles Carmakal, chief technology officer, Mandiant

That advice cuts against instinct: patching alone will close the holes but will not remove a web shell an attacker already planted. Mandiant is urging administrators to check for unauthorized PHP files, unexplained changes to permissions on core system files, and unfamiliar Python processes before they apply Citrix's update — and to treat any appliance that shows those signs as already compromised.

SHARE THIS ARTICLE X Facebook LinkedIn Copy link
Claire Fontaine · Technology & Regulation Correspondent

Reports on technology and its regulation for UBStandard, with a focus on Brussels, AI policy and Europe's digital economy.

[email protected]
Related coverage Front page →