Skip to content

Security21 publishersWidely confirmed2 min readPublished Updated

NetScaler attackers tunnel into internal networks with a new Python proxy

Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying NetScaler attackers tunnel into internal networks with a new Python proxy
Generated illustration

What happened

  • Targets span government, financial services, technology, education, and legal and professional services organizations across North America and Europe.
  • watchTowr Labs traces the flaw to a memory overflow in how the NetScaler Packet Processing Engine handles DTLS traffic.
  • The installer rewrites the appliance's httpd.conf so it runs Debian .deb package files as PHP, then stages web shells with misleading extensions in the VPN scripts directory.
  • For persistence, the operator loosens permissions on /bin/sh through the installer web shells and reboots the entire appliance to lock in root.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The tunneler gives the operator a path to internal hosts and the credentials used to reach them, so the exposed surface is the whole network segment behind the appliance.
  • constraint Applying the fix removes the vulnerability but not a shell already installed, and the /bin/sh change plus a forced reboot were built so root outlasts a restart.
  • decision Owners of internet-facing appliances have a hunt to run, not just an update to apply, since a prior breach shows up as artifacts like slow, kilobyte-sized 404 responses that patching will never flag.

The two tools split the work. WHIPSHOT, a PHP web shell, pulls Base64-encoded commands out of native HTTP headers, runs them, and returns the output [6]. SLAPSHOT, a Python tunneler, takes its orders from WHIPSHOT and forwards arbitrary TCP streams to internal hosts [7]. Google says it watched the actor relay traffic through that proxy in one incident to run internal reconnaissance and steal credentials by hand [8]. If no session or command arrives within ten minutes, SLAPSHOT removes its port and lock files and shuts down, thinning the forensic trail [15].

Installation hides inside ordinary web-server config. One variant enables the mod_php engine, registers .sig files as executable PHP, and maps inbound .ico image requests under /vpn/media/ onto matching .sig files [10]. "For example, clients accessing /vpn/media/e6ee7c85.ico would be served by the dropped PHP web shell e6ee7c85.sig," Google said [11].

The disguise leaves traces in the logs. "In at least one case, web server access logs showed GET requests returning HTTP 404 responses, but exhibiting elevated processing durations and multi-kilobyte response sizes," Google said [13]. The same logs point past a single victim. "In subsequent days, the actor attempted access to non-existent .sig files, which generated missing-file errors in httperror-vpn logs implying the files were not there. This may be an indication of attackers managing similar web shells in multiple compromised environments," Google said [14].

The flaw hands over root before authentication. "Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access," Google said [3]. The trigger sits in the DTLS handshake: "transmitting specially malformed or fragmented record headers induces heap memory boundary corruption within the packet engine, diverting control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform," Google said [5].

Google places the incident in a wider run on internet-facing gear. "This campaign underscores the continued targeting of edge devices to gain initial access to victim networks," Google said [16].

What to watch

  • Attribution: whether Mandiant or Citrix ties CVE-2026-88772 exploitation to a named group or state actor.
  • Whether CISA adds CVE-2026-88772 to its Known Exploited Vulnerabilities catalog with a patch deadline.
  • The victim count as Google works the telemetry pointing to shells in multiple compromised environments.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence88
Adoption82
Hype gap−8
Incentives58
Confidence85

Perspective Coverage

21 publishers
Builder
Builder 30%
Operator
Operator 62%
Investor
Investor 8%
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Unknown threat actors have been exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances.

  2. [2]

    The activity, observed by Mandiant Consulting and the Google Threat Intelligence Group in September 2026, targeted government, financial services, technology, education, and legal and professional services organizations in North America and Europe.

    ReportedSupportedSource: Mandiant Consulting and Google Threat Intelligence Group3 sources— create a free account to open themView cited source
  3. [3]

    Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access.

Sources

21 independent publishers whose own reporting we read for this story.

  1. bleepingcomputer.com

    3 articles · September 29, 2026

    Citrix confirms two critical NetScaler zero-day RCE vulnerabilities are being exploited in attacks, says it has released security updates to fix the flaws
  2. blog.rapid7.com

    1 article · September 28, 2026

    Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772
  3. cert.europa.eu

    1 article

    CERT-EU - Critical Vulnerabilities in Citrix NetScaler ADC and Gateway
  4. cisa.gov

    2 articles · September 27, 2026

    CISA Adds Two Known Exploited Vulnerabilities to Catalog
  5. cyberdaily.au

    1 article · September 27, 2026

    Act now! ACSC and CISA urge immediate action over raft of new Citrix NetScaler ADC and Gateway vulnerabilities - Cyber Daily
  6. cyberscoop.com

    3 articles · September 29, 2026

    Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings | CyberScoop
  7. helpnetsecurity.com

    3 articles · September 30, 2026

    Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) - Help Net Security
  8. infosecurity-magazine.com

    2 articles · September 28, 2026

    Citrix Patches Critical Zero Days Under Active Exploitation - Infosecurity Magazine
  9. itnews.com.au

    1 article

    Citrix confirms exploitation of Netscaler zero-day bugs - iTnews
  10. nakedsecurity.sophos.com

    1 article · September 27, 2026

    Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation
  11. ncsc.gov.uk

    1 article · September 27, 2026

    Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway | National Cyber Security Centre
  12. networkworld.com

    1 article · September 28, 2026

    NetScaler admins told to patch critical zero-days in ADC and Gateway now | Network World
  13. orca.security

    1 article · September 29, 2026

    Critical Citrix NetScaler Zero-Days Under Active Exploitation
  14. scworld.com

    2 articles · September 30, 2026

    CISA warns organizations to patch 2 critical Citrix NetScaler RCEs
  15. securityaffairs.com

    3 articles · September 30, 2026

    U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
  16. securityweek.com

    3 articles · September 30, 2026

    Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug - SecurityWeek
  17. support.citrix.com

    1 article · September 27, 2026

    Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778
  18. thecyberexpress.com

    2 articles · September 28, 2026

    Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack
  19. thehackernews.com

    5 articles · September 30, 2026

    CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
  20. therecord.media

    1 article · September 28, 2026

    US, UK warn of exploited Citrix NetScaler zero-day bugs
  21. unit42.paloaltonetworks.com

    1 article · September 28, 2026

    Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories