Security21 publishersWidely confirmed2 min readPublished Updated
NetScaler attackers tunnel into internal networks with a new Python proxy
Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.
The Watch · Security desk

What happened
- Targets span government, financial services, technology, education, and legal and professional services organizations across North America and Europe.
- watchTowr Labs traces the flaw to a memory overflow in how the NetScaler Packet Processing Engine handles DTLS traffic.
- The installer rewrites the appliance's httpd.conf so it runs Debian .deb package files as PHP, then stages web shells with misleading extensions in the VPN scripts directory.
- For persistence, the operator loosens permissions on /bin/sh through the installer web shells and reboots the entire appliance to lock in root.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The tunneler gives the operator a path to internal hosts and the credentials used to reach them, so the exposed surface is the whole network segment behind the appliance.
- constraint Applying the fix removes the vulnerability but not a shell already installed, and the /bin/sh change plus a forced reboot were built so root outlasts a restart.
- decision Owners of internet-facing appliances have a hunt to run, not just an update to apply, since a prior breach shows up as artifacts like slow, kilobyte-sized 404 responses that patching will never flag.
The two tools split the work. WHIPSHOT, a PHP web shell, pulls Base64-encoded commands out of native HTTP headers, runs them, and returns the output [6]. SLAPSHOT, a Python tunneler, takes its orders from WHIPSHOT and forwards arbitrary TCP streams to internal hosts [7]. Google says it watched the actor relay traffic through that proxy in one incident to run internal reconnaissance and steal credentials by hand [8]. If no session or command arrives within ten minutes, SLAPSHOT removes its port and lock files and shuts down, thinning the forensic trail [15].
Installation hides inside ordinary web-server config. One variant enables the mod_php engine, registers .sig files as executable PHP, and maps inbound .ico image requests under /vpn/media/ onto matching .sig files [10]. "For example, clients accessing /vpn/media/e6ee7c85.ico would be served by the dropped PHP web shell e6ee7c85.sig," Google said [11].
The disguise leaves traces in the logs. "In at least one case, web server access logs showed GET requests returning HTTP 404 responses, but exhibiting elevated processing durations and multi-kilobyte response sizes," Google said [13]. The same logs point past a single victim. "In subsequent days, the actor attempted access to non-existent .sig files, which generated missing-file errors in httperror-vpn logs implying the files were not there. This may be an indication of attackers managing similar web shells in multiple compromised environments," Google said [14].
The flaw hands over root before authentication. "Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access," Google said [3]. The trigger sits in the DTLS handshake: "transmitting specially malformed or fragmented record headers induces heap memory boundary corruption within the packet engine, diverting control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform," Google said [5].
Google places the incident in a wider run on internet-facing gear. "This campaign underscores the continued targeting of edge devices to gain initial access to victim networks," Google said [16].
What to watch
- Attribution: whether Mandiant or Citrix ties CVE-2026-88772 exploitation to a named group or state actor.
- Whether CISA adds CVE-2026-88772 to its Known Exploited Vulnerabilities catalog with a patch deadline.
- The victim count as Google works the telemetry pointing to shells in multiple compromised environments.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence88
- Adoption82
- Hype gap−8
- Incentives58
- Confidence85
Perspective Coverage
21 publishers- Builder
- Builder 30%
- Operator
- Operator 62%
- Investor
- Investor 8%
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Unknown threat actors have been exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances.
- [2]
The activity, observed by Mandiant Consulting and the Google Threat Intelligence Group in September 2026, targeted government, financial services, technology, education, and legal and professional services organizations in North America and Europe.
ReportedSupportedSource: Mandiant Consulting and Google Threat Intelligence Group3 sources— create a free account to open themView cited source - [3]
Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access.
- [4]
watchTowr Labs described CVE-2026-88772 (CVSS score 9.5) as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling in the NSPPE component.
ReportedSupportedSource: watchTowr Labs3 sources— create a free account to open themView cited source - [5]
Analysis of frontline telemetry suggests that transmitting specially malformed or fragmented record headers induces heap memory boundary corruption within the packet engine, diverting control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform.
- [6]
WHIPSHOT is a previously unreported PHP web shell that extracts Base64-encoded command-and-control commands and payloads from native HTTP headers, executes them, and returns the results.
- [7]
SLAPSHOT is a novel Python TCP tunneler that accepts commands from WHIPSHOT and forwards arbitrary TCP streams to internal hosts to enable reconnaissance, lateral movement, and credential harvesting.
- [8]
In at least one case observed by Google, the threat actor relayed traffic through the SLAPSHOT proxy to manually conduct internal reconnaissance and credential theft.
- [9]
The initial installer modifies target httpd.conf files so the appliance handles Debian .deb package files as PHP scripts, then stages web shells with deceptive file extensions in /netscaler/gui/vpn/scripts/linux.
- [10]
A second variant enables the mod_php engine, registers .sig files as executable PHP scripts, and maps incoming HTTP requests ending in .ico under /vpn/media/ to a matching .sig file inside the VPN scripts directory.
- [11]
For example, clients accessing /vpn/media/e6ee7c85.ico would be served by the dropped PHP web shell e6ee7c85.sig.
- [12]
The attack chain establishes persistent root-level execution by using the installer web shells to alter the permissions of /bin/sh and then triggering a full appliance reboot.
- [13]
In at least one case, web server access logs showed GET requests returning HTTP 404 responses, but exhibiting elevated processing durations and multi-kilobyte response sizes.
- [14]
In subsequent days, the actor attempted access to non-existent .sig files, which generated missing-file errors in httperror-vpn logs implying the files were not there. This may be an indication of attackers managing similar web shells in multiple compromised environments.
- [15]
If no active sessions or commands are received within 10 minutes, the malware removes its port and lock files and terminates its process to cover its tracks and minimize forensic traces.
- [16]
This campaign underscores the continued targeting of edge devices to gain initial access to victim networks.
Sources
21 independent publishers whose own reporting we read for this story.
- bleepingcomputer.comCitrix confirms two critical NetScaler zero-day RCE vulnerabilities are being exploited in attacks, says it has released security updates to fix the flaws
3 articles · September 29, 2026
- blog.rapid7.comZero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772
1 article · September 28, 2026
- CERT-EU - Critical Vulnerabilities in Citrix NetScaler ADC and Gateway
cert.europa.eu
1 article
- cisa.govCISA Adds Two Known Exploited Vulnerabilities to Catalog
2 articles · September 27, 2026
- cyberdaily.auAct now! ACSC and CISA urge immediate action over raft of new Citrix NetScaler ADC and Gateway vulnerabilities - Cyber Daily
1 article · September 27, 2026
- cyberscoop.comCitrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings | CyberScoop
3 articles · September 29, 2026
- helpnetsecurity.comCitrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) - Help Net Security
3 articles · September 30, 2026
- infosecurity-magazine.comCitrix Patches Critical Zero Days Under Active Exploitation - Infosecurity Magazine
2 articles · September 28, 2026
- itnews.com.auCitrix confirms exploitation of Netscaler zero-day bugs - iTnews
1 article
- nakedsecurity.sophos.comCitrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation
1 article · September 27, 2026
- Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway | National Cyber Security Centre
ncsc.gov.uk
1 article · September 27, 2026
- networkworld.comNetScaler admins told to patch critical zero-days in ADC and Gateway now | Network World
1 article · September 28, 2026
- orca.securityCritical Citrix NetScaler Zero-Days Under Active Exploitation
1 article · September 29, 2026
- scworld.comCISA warns organizations to patch 2 critical Citrix NetScaler RCEs
2 articles · September 30, 2026
- securityaffairs.comU.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
3 articles · September 30, 2026
- securityweek.comCitrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug - SecurityWeek
3 articles · September 30, 2026
- Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778
support.citrix.com
1 article · September 27, 2026
- thecyberexpress.comCitrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack
2 articles · September 28, 2026
- thehackernews.comCISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
5 articles · September 30, 2026
- therecord.mediaUS, UK warn of exploited Citrix NetScaler zero-day bugs
1 article · September 28, 2026
- unit42.paloaltonetworks.comThreat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild
1 article · September 28, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.