Threat reportVulnerabilityTL-2026-3189

Active Exploitation of Citrix NetScaler ADC and Gateway Zero-Days (CVE-2026-88771, CVE-2026-88772) with WHIPSHOT/SLAPSHOT Post-Exploitation

criticalACTIVE

Active Exploitation of Citrix NetScaler ADC and Gateway (TL-2026-3189), also tracked as NetScaler DTLS zero-day, is a critical-severity software vulnerability scored CVSS 9.5, first published 2026-10-10. It has no confirmed attribution, affects Citrix / Cloud Software Group NetScaler ADC, references 2 CVEs (CVE-2026-88771, CVE-2026-88772), maps to 13 MITRE ATT&CK techniques (T1027.010, T1036.008, T1046), and is covered by 9 detection rules and 13 indicators of compromise.

CVSS
9.5/10Critical
CVEs
2Referenced vulnerabilities
Techniques
13MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
13Indicators of compromise

Key facts for TL-2026-3189

Threat ID
TL-2026-3189
Also known as
NetScaler DTLS zero-day, WHIPSHOT/SLAPSHOT campaign
Severity
CRITICAL
CVSS
9.5 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, financial services, technology, education, legal and professional services
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
13

Malware and tooling in Active Exploitation of Citrix NetScaler ADC and Gateway

Malware and tooling: SLAPSHOT, WHIPSHOT

How Active Exploitation of Citrix NetScaler ADC and Gateway works

Google Threat Intelligence Group and Mandiant report in-the-wild exploitation of two NetScaler ADC and Gateway zero-days since early September 2026. CVE-2026-88772 is a pre-authentication DTLS heap overflow in NSPPE (UDP/443) yielding root shellcode execution, followed by Apache config persistence, the WHIPSHOT PHP web shell and the SLAPSHOT Python TCP tunneler.

Mandiant Consulting and GTIG identified exploitation of CVE-2026-88772, a pre-authentication memory overflow (CWE-119) in the DTLS handling of the NetScaler Packet Processing Engine (NSPPE), reachable over UDP/443. Attackers send malformed or fragmented DTLS record headers during the initial handshake; the resulting heap boundary corruption diverts control flow to attacker shellcode running with root privileges on the underlying FreeBSD OS. Public technical analysis (watchTowr, as reported by The Hacker News) describes a fragment_length field that contradicts the actual handshake message length, so a 120-byte handshake message can be split into many one-byte fragments that overflow a 35,840-byte buffer, with mprotect() used to bypass NX. A public PoC has been published. DTLS is enabled by default on VPN virtual servers. Exploitation leaves SSL_HANDSHAKE_FAILURE syslog entries (ClientVersion DTLSv1.0, Reason 'Handshake failure-Internal Error') and NSPPE process exits with 'pitboss ... NOT restarting NSPPE' messages in /var/log/messages.

CVE-2026-88771 is a second, also actively exploited, pre-authentication flaw (CWE-20, improper input validation). Per vendor and third-party reporting, the ns_monuploadd_err.pl log-processing script concatenates NSPPE crash core file names taken from system logs into shell commands, so attacker-controlled strings written to logs through unauthenticated interfaces lead to root command execution. Citrix published bulletin CTX697096 on 2026-09-27 covering CVE-2026-88771 through CVE-2026-88778, and CISA added both exploited CVEs to the KEV catalog the same day with a 2026-09-30 due date and forensic-triage requirements under BOD 26-04.

After gaining root, the payload modifies /etc/httpd.conf to enable php_flag engine on and register non-PHP extensions as PHP handlers: either .deb files staged in the client plug-in directory /var/netscaler/gui/vpn/scripts/linux/, or .sig files exposed through an AliasMatch that maps /vpn/media/<name>.ico requests to <name>.sig. Persistence also uses chmod u+s /bin/sh, httpd restart via /bin/httpd -k restart -f /etc/httpd.conf, and an appliance reboot via /netscaler/nsshutdown -R. A regex scrubber removes installation-path lines from /etc/crontab.

WHIPSHOT is a PHP web shell that reads Base64 commands from HTTP headers (HTTP_NSC_LDAP for nsginstaller*.deb variants, HTTP_NSC_CLIENTTYPE for nsgclient.sig, HTTP_X_UX and HTTP_X_UX_<n> for chunked transport), suppresses errors, returns HTTP 404 despite successful execution, and relays to a local tunneler over loopback via the port in /tmp/.uxdport. SLAPSHOT is a Python daemon launched with nohup and a Base64 exec stub; it binds an ephemeral port on 127.0.0.1, records it in /tmp/.uxdport, holds an flock on /tmp/.uxdlock, and speaks a 4-byte big-endian length-prefixed JSON protocol (open, push, pull, exch, close, ping with sid/host/port/data fields). It exits after 10 minutes without commands (UXD_IDLE_EXIT) and closes idle sessions after 15 minutes. It is used for internal network reconnaissance and credential theft pivoting. Scanning/staging activity was observed from 143.198.7.94 and exploitation/installation from 157.254.167.12. The source does not attribute the activity to a named actor.

MITRE ATT&CK techniques used in TL-2026-3189

Defense Evasion

T1027.010 Obfuscated Files or Information: Command Obfuscation; T1036.008 Masquerading: Masquerade File Type; T1070.009 Indicator Removal: Clear Persistence

Discovery

T1046 Network Service Discovery

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.006 Command and Scripting Interpreter: Python; T1203 Exploitation for Client Execution

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090.001 Proxy: Internal Proxy; T1132.001 Data Encoding: Standard Encoding

Initial Access

T1190 Exploit Public-Facing Application

Persistence

T1505.003 Server Software Component: Web Shell

Privilege Escalation

T1548.001 Abuse Elevation Control Mechanism: Setuid and Setgid

Affected products and versions in Active Exploitation of Citrix NetScaler ADC and Gateway

  • Citrix / Cloud Software Group — NetScaler ADC
    Vulnerable versions: 14.1 before 14.1-73.37; 13.1 before 13.1-64.23; 13.1-FIPS/NDcPP before 13.1-37.279
    Fixed in: 14.1-73.37 and later; 13.1-64.23 and later; 13.1-37.279 and later (FIPS/NDcPP)
  • Citrix / Cloud Software Group — NetScaler Gateway
    Vulnerable versions: 14.1 before 14.1-73.37; 13.1 before 13.1-64.23
    Fixed in: 14.1-73.37 and later; 13.1-64.23 and later

Remediation for Active Exploitation of Citrix NetScaler ADC and Gateway

Patches

  • Citrix Security Bulletin CTX697096 covering CVE-2026-88771 through CVE-2026-88778
  • NetScaler 14.1-73.37 and later; NetScaler 13.1-64.23 and later

Immediate actions

  • Upgrade NetScaler ADC and Gateway to 14.1-73.37 or later, or 13.1-64.23 or later (FIPS/NDcPP: 13.1-37.279 or later)
  • Disable DTLS where operationally feasible or block inbound UDP/443 upstream as a compensating control for CVE-2026-88772
  • Isolate confirmed or suspected compromised appliances, disable HA synchronization and preserve VM snapshots with memory for forensics
  • Run the Citrix IOC scanner in NetScaler Console and conduct forensic triage per CISA BOD 26-04
  • Hunt for WHIPSHOT and SLAPSHOT artifacts: /tmp/.uxdport, /tmp/.uxdlock, SUID bit on /bin/sh, php_flag/AddHandler/AliasMatch in /etc/httpd.conf

Workarounds

  • Disable DTLS on VPN virtual servers (mitigates CVE-2026-88772 only)
  • Revoke administrative, Gateway, VPN and ICA/HDX sessions (Citrix CTX584227) and rotate admin, SSH, TLS, LDAP/RADIUS/TACACS credentials and SNMP strings on suspected compromise

Longer-term hardening

  • Apply default-deny outbound filtering from NSIP/SNIP addresses and block outbound SMTP/TCP:25
  • Keep NSIP and management interfaces off the internet and restrict SSH/HTTPS management to dedicated networks
  • Forward ns.log, /var/log/messages, httpaccess.log, httperror* and PAM audit logs to the SIEM
  • Monitor the VPN script and media directories and httpd.conf for file integrity changes

CVEs associated with Active Exploitation of Citrix NetScaler ADC and Gateway

CVE-2026-88771, CVE-2026-88772

Weaknesses (CWE) in Active Exploitation of Citrix NetScaler ADC and Gateway

CWE-20, CWE-119

Timeline of Active Exploitation of Citrix NetScaler ADC and Gateway

  • Exploitation of NetScaler appliances begins in early September 2026, per Mandiant/GTIG (exact day not stated in the source; date is approximate)
  • CISA adds CVE-2026-88771 and CVE-2026-88772 to the KEV catalog with a 2026-09-30 due date and BOD 26-04 forensic triage requirement
  • Citrix publishes security bulletin CTX697096 covering CVE-2026-88771 through CVE-2026-88778 and reports exploitation on unmitigated deployments
  • Bitsight and other vendors publish alerts confirming active exploitation of both flaws
  • Google Cloud Threat Intelligence (Mandiant/GTIG) publishes analysis of the exploitation, WHIPSHOT and SLAPSHOT, IOCs, hunting commands and YARA rules
  • Technical analysis and PoC code for CVE-2026-88772 published by watchTowr, as reported by The Hacker News; CISA KEV remediation deadline

Sources cited for Active Exploitation of Citrix NetScaler ADC and Gateway

Detection coverage for TL-2026-3189

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3189 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
13 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats