NetScaler CVE-2026-88772 Exploitation Deploys Root Malware
Attackers are actively exploiting a critical Citrix NetScaler zero-day, CVE-2026-88772, to gain root access and deploy custom WHIPSHOT and SLAPSHOT malware

Threat actors are exploiting a critical zero-day in Citrix NetScaler appliances to achieve root-level access and deploy custom malware. The vulnerability, tracked as CVE-2026-88772 with a CVSS score of 9.5, is a memory overflow bug in the DTLS protocol handling within the NetScaler Packet Processing Engine (NSPPE).
Exploitation began in early September 2026. By late last week, organizations across North America and Europe in government, finance, education, telecom, legal, and professional services were likely compromised. The flaw is triggered during the initial DTLS handshake, before any login is required. Google stated: "Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access."
A malformed or fragmented DTLS record header corrupts heap memory in the packet engine. This diverts control flow to execute arbitrary shellcode with root privileges on the underlying FreeBSD platform. The bug affects appliances with DTLS enabled, which is the default for NetScaler Gateway VPN virtual servers. Successful exploitation attempts generate specific log artifacts, including an SSL handshake failure for DTLSv1.0 with the reason 'Handshake failure-Internal Error' and a subsequent crash of the packet engine process.
Malware Deployment Chain
Following a successful exploit, attackers install a persistent web shell. The initial payload modifies the appliance's Apache configuration to treat specific file types as executable PHP scripts. In some intrusions.deb files were registered as PHP. A stealthier method uses.sig files and adds a redirect so requests for a.ico icon file are served by the hidden shell.
For example, a client accessing /vpn/media/e6ee7c85.ico would be served by the dropped PHP web shell e6ee7c85.sig. This activity can be detected by anomalies in web server logs. Google noted that in at least one case, "web server access logs showed GET requests returning HTTP 404 responses, but exhibiting elevated processing durations and multi-kilobyte response sizes."
To maintain root access across reboots, the installer makes /bin/sh setuid and forces a full appliance restart. Attackers then deploy two custom tools: WHIPSHOT and SLAPSHOT. Mandiant had not seen either tool prior to this campaign.
WHIPSHOT disguises its command-and-control payloads within native HTTP headers. It disables error reporting and always returns a 404 status to avoid detection in logs. SLAPSHOT accepts commands from WHIPSHOT to tunnel traffic. It closes idle sessions after 15 minutes and will shut down entirely, deleting its own files, after 10 minutes of no activity.
Threat Intelligence Assessment
Exploitation has escalated from reconnaissance to widespread malware deployment. GreyNoise observed a significant surge in malicious activity linked to CVE-2026-88772 beginning on September 28, 2026, around 8:30 a.m. EDT, with a major peak the same day at 10:30 p.m. EDT. The activity involves multiple independent actors and campaigns.
The GreyNoise team said: What started as mass reconnaissance yesterday has now evolved into full-on mass exploitation across a multitude of independent actors and campaigns.
In at least one confirmed case, threat actors used the SLAPSHOT tunnel to conduct manual internal reconnaissance and credential theft. The connection originated from the compromised internet-facing gateway, providing a direct conduit into the victim's internal network. Attempts to access non-existent .sig files in other environments suggest attackers may be managing similar web shells across multiple compromised systems.
Edge devices like VPN gateways remain prime targets because they are internet-exposed, often sit outside endpoint detection tools, and can store credentials for deeper network access. While disabling DTLS and blocking inbound UDP/443 can mitigate this specific attack vector, it does not protect against a second, concurrently exploited zero-day tracked as CVE-2026-88771. Security teams are advised to continue monitoring for signs of CVE-2026-88772 exploitation and the deployment of the WHIPSHOT and SLAPSHOT malware.





