Security researchers have detailed active exploitation of a critical Citrix NetScaler ADC and Gateway vulnerability that attackers used to gain root access, deploy web shells, and move laterally into victim networks. The flaw, tracked as CVE-2026-88772 (CVSS 9.5), is a memory overflow bug in how NetScaler handles Datagram Transport Layer Security (DTLS) when the protocol is enabled.
Citrix disclosed CVE-2026-88772 alongside a second zero-day, CVE-2026-88771, an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments. Some researchers have nicknamed the pair “PitScaler.” Citrix has confirmed both were exploited on unmitigated appliances prior to the release of security updates.
Timeline of exploitation
GreyNoise says it observed exploitation attempts against a NetScaler Gateway on September 24, three days before Citrix publicly disclosed the flaws, and detected the activity before CVE-specific signatures existed. The attack, originating from IP address 149.104.78.141, attempted to modify /bin/sh to obtain a root shell and install a password-protected PHP web shell at a hidden path inside the NetScaler logon portal directory. The attacker also altered the httpd.conf configuration so that requests appearing to be CSS files would silently load the hidden web shell instead.
Mandiant, which says the broader campaign began in at least early September, reports that attacks have hit organizations across North America and Europe in government, financial services, education, legal, and professional services sectors. According to Mandiant’s analysis, exploitation of CVE-2026-88772 bypasses authentication and crashes the NetScaler Packet Processing Engine, corrupting heap memory boundaries and redirecting control flow to execute arbitrary shellcode with root privileges on the underlying FreeBSD operating system.
Web shells disguised as images and packages
Post-exploitation activity observed by Mandiant closely mirrors what GreyNoise documented. In multiple intrusions, attackers modified the NetScaler web server configuration so that non-executable file types, including .deb and .sig files, and image requests under the VPN media directory, would instead be processed as PHP. This let malicious web shell traffic masquerade as routine requests for CSS or icon files while executing commands through PHP’s shell_exec() or eval() functions. Some web shells returned fake HTTP 404 responses to mask successful command execution.
Mandiant identified two previously undocumented malware families used in the campaign, WHIPSHOT and SLAPSHOT. WHIPSHOT is a PHP web shell disguised as a Debian package and planted in the NetScaler VPN scripts directory.
Defenders are urged to apply Citrix’s patches immediately, hunt for unauthorized web shell files and modified httpd.conf entries referencing Alias or AliasMatch directives, check for unexpected permission changes to /bin/sh, and review logs for connections from the identified malicious IP address.
