"Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access," Google said.
CVE-2026-88772: a DTLS memory overflow with root consequences
Security researchers from Mandiant Consulting and the Google Threat Intelligence Group (GTIG) observed attackers exploiting CVE-2026-88772 in September 2026 to gain root on Citrix NetScaler ADC and NetScaler Gateway appliances deployed across North America and Europe. WatchTowr Labs assigned the vulnerability a CVSS score of 9.5 and described it as a memory overflow bug in Datagram Transport Layer Security (DTLS) protocol handling within the NetScaler Packet Processing Engine (NSPPE).
GTIG's technical description states that "during the initial pre-authentication cryptographic handshake, the NSPPE parses inbound DTLS record structures" and that specially malformed or fragmented DTLS record headers can induce heap memory boundary corruption. That corruption, the report says, can divert control flow and permit execution of arbitrary shellcode with root privileges on the appliance's underlying FreeBSD platform.
WHIPSHOT and SLAPSHOT: two new post-exploitation tools
Once root is achieved, the attackers deploy a lightweight post-exploitation toolkit that includes previously unreported components named WHIPSHOT and SLAPSHOT. WHIPSHOT is a PHP web shell that can extract Base64-encoded commands and payloads from native HTTP headers, execute them on the appliance, and return results. SLAPSHOT is a Python-based TCP tunneler that acts as an internal network bridge, accepting commands from WHIPSHOT and forwarding arbitrary TCP streams to hosts inside the victim network.
The two tools are used together: WHIPSHOT provides remote command-and-control, and SLAPSHOT proxies traffic into internal networks for reconnaissance, lateral movement, and credential theft. In at least one observed case, GTIG said the actor relayed traffic through SLAPSHOT to manually conduct internal reconnaissance and credential theft. SLAPSHOT is also designed to self-clean if idle—removing its port and lock files and terminating if no sessions or commands are received within ten minutes.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildAttack chain and persistence techniques on NetScaler appliances
GTIG details a repeatable attack chain. After exploiting the NSPPE DTLS bug, an installer web shell modifies httpd.conf so that Debian package files (.deb) and signature files (.sig) are handled as PHP scripts under the appliance webroot. The researchers observed web shells staged in "/netscaler/gui/vpn/scripts/linux" disguised with deceptive file extensions such as .deb and .sig.
In some cases the attacker added a configuration hook that maps requests for .ico files under "/vpn/media/" to identically named .sig files inside "/var/netscaler/gui/vpn/scripts/linux/". GTIG offered a concrete example: a client requesting /vpn/media/e6ee7c85.ico would be served by the PHP web shell e6ee7c85.sig. GTIG also flagged log anomalies: GET requests that returned HTTP 404 responses yet exhibited elevated processing durations and multi-kilobyte response sizes, and later attempts that generated missing-file errors in httperror-vpn logs—behavior consistent with web shells managed across multiple compromised environments.
To achieve persistence and root-level execution for their web shells, attackers altered permissions of /bin/sh and then initiated a full NetScaler appliance reboot, ensuring continued access after system restarts.
Observed targets, timeline, and actor motivations
Mandiant and GTIG reported that the activity targeted government, financial services, technology, education, and legal and professional services sectors. GreyNoise traced a wider pattern of malicious activity linked to CVE-2026-88771 and CVE-2026-88772 beginning September 28, 2026, around 8:30 a.m. EDT, with a significant surge later that day at approximately 10:30 p.m. EDT.
GreyNoise characterized the evolution as: "What started as mass reconnaissance yesterday has now evolved into full-on mass exploitation across a multitude of independent actors and campaigns," and reported wide-scale web shell and malware deployment for "the primary purposes of botnet recruitment and access brokering."
What this means for government, financial services, and technology organizations
- Government agencies: appliances exposed to the internet and hosting VPN gateway functions may be attractive initial-access points; logs described by GTIG (404 responses with long processing times and multi-kilobyte responses, missing-file errors in httperror-vpn) are actionable indicators to inspect.
- Financial services: because appliances "often store or process credentials" and sit outside endpoint detection and response, GTIG's findings indicate credential harvesting via SLAPSHOT could enable deeper network access and escalate fraud or data-theft risk.
- Technology companies: organizations operating Citrix NetScaler ADC or Gateway should treat the DTLS handling bug as high-severity (CVSS 9.5), validate appliance configurations for unexpected httpd.conf changes, and hunt for file-mapped web shells (e.g., .deb/.sig files in /netscaler/gui/vpn/scripts/linux).
This campaign underscores a persistent theme in recent intrusions: edge appliances—Application Delivery Controllers, VPN gateways, and firewalls—remain high-value targets because they are internet-exposed, frequently outside EDR coverage, and can hold or mediate credentials useful for further compromise, GTIG warned. The concrete artifacts and behaviors GTIG and GreyNoise published—CVE identifiers, file-mapping tricks, and the names WHIPSHOT and SLAPSHOT—offer defenders precise signals to search for in affected fleets.
Source: https://thehackernews.com/2026/09/attackers-exploit-netscaler-flaw-for.html




