Hackers are breaking into Citrix NetScaler appliances at government agencies, banks, universities and law firms across North America and Europe, using a pair of previously unknown flaws to seize root-level control and plant two custom hacking tools researchers had never seen before.
Citrix disclosed the two vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, on September 27 and released patches the same day. Both carry a CVSS severity score of 9.5. CVE-2026-88771 lets an attacker execute code on a vulnerable NetScaler ADC or Gateway appliance in its default configuration; CVE-2026-88772 is a memory-overflow bug, triggered by malformed encrypted handshake data, that corrupts the appliance's packet-processing engine and hands an attacker root access on the underlying operating system. The U.S. Cybersecurity and Infrastructure Security Agency added both to its Known Exploited Vulnerabilities catalog the day they were disclosed.
Two New Tools, Built to Hide
Mandiant and Google's Threat Intelligence Group, which found the campaign, say attackers began exploiting the flaws as early as September 24 — three days before Citrix told the public — and that activity surged into what the threat-intelligence firm GreyNoise described as mass exploitation by multiple, apparently unrelated attackers. Once inside, intruders installed a web shell the researchers named WHIPSHOT, a program disguised as an ordinary Debian software package that hides commands inside HTTP headers, and a companion tool called SLAPSHOT, which tunnels traffic to other machines on the victim's internal network and erases its own traces after roughly ten minutes of inactivity.
The intrusions gave attackers a foothold to explore victims' internal networks and harvest credentials, according to Google's threat-intelligence writeup, though the companies have not said how many organizations were ultimately compromised beyond describing victims in government, financial services, education and professional-services sectors.
Security researchers were also frustrated by how long the flaws went undisclosed. "Why Citrix took so long to disclose these vulnerabilities is a question only Citrix can answer," said Benjamin Harris, chief executive of the security firm watchTowr, in comments reported by The Register.
"NetScaler customers should prioritize examining systems for compromise before upgrading/patching."
Charles Carmakal, chief technology officer, Mandiant
That advice cuts against instinct: patching alone will close the holes but will not remove a web shell an attacker already planted. Mandiant is urging administrators to check for unauthorized PHP files, unexplained changes to permissions on core system files, and unfamiliar Python processes before they apply Citrix's update — and to treat any appliance that shows those signs as already compromised.