Threat reportVulnerabilityTL-2026-3189
Active Exploitation of Citrix NetScaler ADC and Gateway Zero-Days (CVE-2026-88771, CVE-2026-88772) with WHIPSHOT/SLAPSHOT Post-Exploitation
Active Exploitation of Citrix NetScaler ADC and Gateway (TL-2026-3189), also tracked as NetScaler DTLS zero-day, is a critical-severity software vulnerability scored CVSS 9.5, first published 2026-10-10. It has no confirmed attribution, affects Citrix / Cloud Software Group NetScaler ADC, references 2 CVEs (CVE-2026-88771, CVE-2026-88772), maps to 13 MITRE ATT&CK techniques (T1027.010, T1036.008, T1046), and is covered by 9 detection rules and 13 indicators of compromise.
- CVSS
- 9.5/10Critical
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 13MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 13Indicators of compromise
Key facts for TL-2026-3189
- Threat ID
- TL-2026-3189
- Also known as
- NetScaler DTLS zero-day, WHIPSHOT/SLAPSHOT campaign
- Severity
- CRITICAL
- CVSS
- 9.5 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, financial services, technology, education, legal and professional services
- Target regions
- North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 13
Malware and tooling in Active Exploitation of Citrix NetScaler ADC and Gateway
Malware and tooling: SLAPSHOT, WHIPSHOT
How Active Exploitation of Citrix NetScaler ADC and Gateway works
Google Threat Intelligence Group and Mandiant report in-the-wild exploitation of two NetScaler ADC and Gateway zero-days since early September 2026. CVE-2026-88772 is a pre-authentication DTLS heap overflow in NSPPE (UDP/443) yielding root shellcode execution, followed by Apache config persistence, the WHIPSHOT PHP web shell and the SLAPSHOT Python TCP tunneler.
Mandiant Consulting and GTIG identified exploitation of CVE-2026-88772, a pre-authentication memory overflow (CWE-119) in the DTLS handling of the NetScaler Packet Processing Engine (NSPPE), reachable over UDP/443. Attackers send malformed or fragmented DTLS record headers during the initial handshake; the resulting heap boundary corruption diverts control flow to attacker shellcode running with root privileges on the underlying FreeBSD OS. Public technical analysis (watchTowr, as reported by The Hacker News) describes a fragment_length field that contradicts the actual handshake message length, so a 120-byte handshake message can be split into many one-byte fragments that overflow a 35,840-byte buffer, with mprotect() used to bypass NX. A public PoC has been published. DTLS is enabled by default on VPN virtual servers. Exploitation leaves SSL_HANDSHAKE_FAILURE syslog entries (ClientVersion DTLSv1.0, Reason 'Handshake failure-Internal Error') and NSPPE process exits with 'pitboss ... NOT restarting NSPPE' messages in /var/log/messages.
CVE-2026-88771 is a second, also actively exploited, pre-authentication flaw (CWE-20, improper input validation). Per vendor and third-party reporting, the ns_monuploadd_err.pl log-processing script concatenates NSPPE crash core file names taken from system logs into shell commands, so attacker-controlled strings written to logs through unauthenticated interfaces lead to root command execution. Citrix published bulletin CTX697096 on 2026-09-27 covering CVE-2026-88771 through CVE-2026-88778, and CISA added both exploited CVEs to the KEV catalog the same day with a 2026-09-30 due date and forensic-triage requirements under BOD 26-04.
After gaining root, the payload modifies /etc/httpd.conf to enable php_flag engine on and register non-PHP extensions as PHP handlers: either .deb files staged in the client plug-in directory /var/netscaler/gui/vpn/scripts/linux/, or .sig files exposed through an AliasMatch that maps /vpn/media/<name>.ico requests to <name>.sig. Persistence also uses chmod u+s /bin/sh, httpd restart via /bin/httpd -k restart -f /etc/httpd.conf, and an appliance reboot via /netscaler/nsshutdown -R. A regex scrubber removes installation-path lines from /etc/crontab.
WHIPSHOT is a PHP web shell that reads Base64 commands from HTTP headers (HTTP_NSC_LDAP for nsginstaller*.deb variants, HTTP_NSC_CLIENTTYPE for nsgclient.sig, HTTP_X_UX and HTTP_X_UX_<n> for chunked transport), suppresses errors, returns HTTP 404 despite successful execution, and relays to a local tunneler over loopback via the port in /tmp/.uxdport. SLAPSHOT is a Python daemon launched with nohup and a Base64 exec stub; it binds an ephemeral port on 127.0.0.1, records it in /tmp/.uxdport, holds an flock on /tmp/.uxdlock, and speaks a 4-byte big-endian length-prefixed JSON protocol (open, push, pull, exch, close, ping with sid/host/port/data fields). It exits after 10 minutes without commands (UXD_IDLE_EXIT) and closes idle sessions after 15 minutes. It is used for internal network reconnaissance and credential theft pivoting. Scanning/staging activity was observed from 143.198.7.94 and exploitation/installation from 157.254.167.12. The source does not attribute the activity to a named actor.
MITRE ATT&CK techniques used in TL-2026-3189
Defense Evasion
T1027.010 Obfuscated Files or Information: Command Obfuscation; T1036.008 Masquerading: Masquerade File Type; T1070.009 Indicator Removal: Clear Persistence
Discovery
T1046 Network Service Discovery
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.006 Command and Scripting Interpreter: Python; T1203 Exploitation for Client Execution
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090.001 Proxy: Internal Proxy; T1132.001 Data Encoding: Standard Encoding
Initial Access
T1190 Exploit Public-Facing Application
Persistence
T1505.003 Server Software Component: Web Shell
Privilege Escalation
T1548.001 Abuse Elevation Control Mechanism: Setuid and Setgid
Affected products and versions in Active Exploitation of Citrix NetScaler ADC and Gateway
- Citrix / Cloud Software Group — NetScaler ADC
Vulnerable versions: 14.1 before 14.1-73.37; 13.1 before 13.1-64.23; 13.1-FIPS/NDcPP before 13.1-37.279
Fixed in: 14.1-73.37 and later; 13.1-64.23 and later; 13.1-37.279 and later (FIPS/NDcPP) - Citrix / Cloud Software Group — NetScaler Gateway
Vulnerable versions: 14.1 before 14.1-73.37; 13.1 before 13.1-64.23
Fixed in: 14.1-73.37 and later; 13.1-64.23 and later
Remediation for Active Exploitation of Citrix NetScaler ADC and Gateway
Patches
- Citrix Security Bulletin CTX697096 covering CVE-2026-88771 through CVE-2026-88778
- NetScaler 14.1-73.37 and later; NetScaler 13.1-64.23 and later
Immediate actions
- Upgrade NetScaler ADC and Gateway to 14.1-73.37 or later, or 13.1-64.23 or later (FIPS/NDcPP: 13.1-37.279 or later)
- Disable DTLS where operationally feasible or block inbound UDP/443 upstream as a compensating control for CVE-2026-88772
- Isolate confirmed or suspected compromised appliances, disable HA synchronization and preserve VM snapshots with memory for forensics
- Run the Citrix IOC scanner in NetScaler Console and conduct forensic triage per CISA BOD 26-04
- Hunt for WHIPSHOT and SLAPSHOT artifacts: /tmp/.uxdport, /tmp/.uxdlock, SUID bit on /bin/sh, php_flag/AddHandler/AliasMatch in /etc/httpd.conf
Workarounds
- Disable DTLS on VPN virtual servers (mitigates CVE-2026-88772 only)
- Revoke administrative, Gateway, VPN and ICA/HDX sessions (Citrix CTX584227) and rotate admin, SSH, TLS, LDAP/RADIUS/TACACS credentials and SNMP strings on suspected compromise
Longer-term hardening
- Apply default-deny outbound filtering from NSIP/SNIP addresses and block outbound SMTP/TCP:25
- Keep NSIP and management interfaces off the internet and restrict SSH/HTTPS management to dedicated networks
- Forward ns.log, /var/log/messages, httpaccess.log, httperror* and PAM audit logs to the SIEM
- Monitor the VPN script and media directories and httpd.conf for file integrity changes
CVEs associated with Active Exploitation of Citrix NetScaler ADC and Gateway
Weaknesses (CWE) in Active Exploitation of Citrix NetScaler ADC and Gateway
Timeline of Active Exploitation of Citrix NetScaler ADC and Gateway
- Exploitation of NetScaler appliances begins in early September 2026, per Mandiant/GTIG (exact day not stated in the source; date is approximate)
- CISA adds CVE-2026-88771 and CVE-2026-88772 to the KEV catalog with a 2026-09-30 due date and BOD 26-04 forensic triage requirement
- Citrix publishes security bulletin CTX697096 covering CVE-2026-88771 through CVE-2026-88778 and reports exploitation on unmitigated deployments
- Bitsight and other vendors publish alerts confirming active exploitation of both flaws
- Google Cloud Threat Intelligence (Mandiant/GTIG) publishes analysis of the exploitation, WHIPSHOT and SLAPSHOT, IOCs, hunting commands and YARA rules
- Technical analysis and PoC code for CVE-2026-88772 published by watchTowr, as reported by The Hacker News; CISA KEV remediation deadline
Sources cited for Active Exploitation of Citrix NetScaler ADC and Gateway
- Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
- Citrix Security Bulletin CTX697096 (CVE-2026-88771 through CVE-2026-88778)
- Citrix Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (TechZone)
- CISA Known Exploited Vulnerabilities Catalog
- Malpedia library entry for the GTIG report
- Citrix NetScaler CVE-2026-88772 exploit (The Hacker News)
- CVE-2026-88771 and CVE-2026-88772: Two Critical Citrix NetScaler Flaws Under Active Exploitation (Bitsight)
- NetScaler CVE-2026-88771 and CVE-2026-88772 (Fortra)
- Citrix NetScaler CVE-2026-88771 / CVE-2026-88772 in active exploitation (Sophos)
Detection coverage for TL-2026-3189
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3189 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.