# Active Exploitation of Citrix NetScaler ADC and Gateway Zero-Days (CVE-2026-88771, CVE-2026-88772) with WHIPSHOT/SLAPSHOT Post-Exploitation

> Google Threat Intelligence Group and Mandiant report in-the-wild exploitation of two NetScaler ADC and Gateway zero-days since early September 2026. CVE-2026-88772 is a pre-authentication DTLS heap overflow in NSPPE (UDP/443) yielding root shellcode execution, followed by Apache config persistence, the WHIPSHOT PHP web shell and the SLAPSHOT Python TCP tunneler.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3189
- **ID:** TL-2026-3189
- **Severity:** CRITICAL (CVSS 9.5)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 13 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-88771, CVE-2026-88772

## Description

Mandiant Consulting and GTIG identified exploitation of CVE-2026-88772, a pre-authentication memory overflow (CWE-119) in the DTLS handling of the NetScaler Packet Processing Engine (NSPPE), reachable over UDP/443. Attackers send malformed or fragmented DTLS record headers during the initial handshake; the resulting heap boundary corruption diverts control flow to attacker shellcode running with root privileges on the underlying FreeBSD OS. Public technical analysis (watchTowr, as reported by The Hacker News) describes a fragment_length field that contradicts the actual handshake message length, so a 120-byte handshake message can be split into many one-byte fragments that overflow a 35,840-byte buffer, with mprotect() used to bypass NX. A public PoC has been published. DTLS is enabled by default on VPN virtual servers. Exploitation leaves SSL_HANDSHAKE_FAILURE syslog entries (ClientVersion DTLSv1.0, Reason 'Handshake failure-Internal Error') and NSPPE process exits with 'pitboss ... NOT restarting NSPPE' messages in /var/log/messages.

CVE-2026-88771 is a second, also actively exploited, pre-authentication flaw (CWE-20, improper input validation). Per vendor and third-party reporting, the ns_monuploadd_err.pl log-processing script concatenates NSPPE crash core file names taken from system logs into shell commands, so attacker-controlled strings written to logs through unauthenticated interfaces lead to root command execution. Citrix published bulletin CTX697096 on 2026-09-27 covering CVE-2026-88771 through CVE-2026-88778, and CISA added both exploited CVEs to the KEV catalog the same day with a 2026-09-30 due date and forensic-triage requirements under BOD 26-04.

After gaining root, the payload modifies /etc/httpd.conf to enable php_flag engine on and register non-PHP extensions as PHP handlers: either .deb files staged in the client plug-in directory /var/netscaler/gui/vpn/scripts/linux/, or .sig files exposed through an AliasMatch that maps /vpn/media/<name>.ico requests to <name>.sig. Persistence also uses chmod u+s /bin/sh, httpd restart via /bin/httpd -k restart -f /etc/httpd.conf, and an appliance reboot via /netscaler/nsshutdown -R. A regex scrubber removes installation-path lines from /etc/crontab.

WHIPSHOT is a PHP web shell that reads Base64 commands from HTTP headers (HTTP_NSC_LDAP for nsginstaller*.deb variants, HTTP_NSC_CLIENTTYPE for nsgclient.sig, HTTP_X_UX and HTTP_X_UX_<n> for chunked transport), suppresses errors, returns HTTP 404 despite successful execution, and relays to a local tunneler over loopback via the port in /tmp/.uxdport. SLAPSHOT is a Python daemon launched with nohup and a Base64 exec stub; it binds an ephemeral port on 127.0.0.1, records it in /tmp/.uxdport, holds an flock on /tmp/.uxdlock, and speaks a 4-byte big-endian length-prefixed JSON protocol (open, push, pull, exch, close, ping with sid/host/port/data fields). It exits after 10 minutes without commands (UXD_IDLE_EXIT) and closes idle sessions after 15 minutes. It is used for internal network reconnaissance and credential theft pivoting. Scanning/staging activity was observed from 143.198.7.94 and exploitation/installation from 157.254.167.12. The source does not attribute the activity to a named actor.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1059.006 Command and Scripting Interpreter: Python
- T1505.003 Server Software Component: Web Shell
- T1548.001 Abuse Elevation Control Mechanism: Setuid and Setgid
- T1036.008 Masquerading: Masquerade File Type
- T1070.009 Indicator Removal: Clear Persistence
- T1027.010 Obfuscated Files or Information: Command Obfuscation
- T1046 Network Service Discovery
- T1071.001 Application Layer Protocol: Web Protocols
- T1090.001 Proxy: Internal Proxy
- T1132.001 Data Encoding: Standard Encoding

## Sources

- [Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances](https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances)
- [Citrix Security Bulletin CTX697096 (CVE-2026-88771 through CVE-2026-88778)](https://support.citrix.com/external/article/CTX697096)
- [Citrix Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (TechZone)](https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)
- [Malpedia library entry for the GTIG report](https://malpedia.caad.fkie.fraunhofer.de/library/040a959b-023e-43a0-8154-ec61a938d2cf/)
- [Citrix NetScaler CVE-2026-88772 exploit (The Hacker News)](https://thehackernews.com/2026/09/citrix-netscaler-cve-2026-88772-exploit.html)
- [CVE-2026-88771 and CVE-2026-88772: Two Critical Citrix NetScaler Flaws Under Active Exploitation (Bitsight)](https://www.bitsight.com/blog/critical-vulnerability-alert-cve-2026-88771-cve-2026-88772-citrix-netscaler-flaws-under-exploitation)
- [NetScaler CVE-2026-88771 and CVE-2026-88772 (Fortra)](https://www.fortra.com/security/emerging-threats/netscaler-cve-2026-88771-improper-input-validation-and-cve-2026-88772)
- [Citrix NetScaler CVE-2026-88771 / CVE-2026-88772 in active exploitation (Sophos)](https://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3189
