WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
Active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances has been observed in the wild. The flaw, CVE-2026-88772 , is a pre-authentication memory overflow in DTLS handling that gives an attacker root-level code execution on the underlying FreeBSD system. A second zero-day, CVE-2026-88771, was reported as exploited alongside it, but the reporting does not link it to the malware described here.
After exploitation, the actors deploy two previously unseen custom tools: WHIPSHOT , a PHP web shell disguised as a Debian package, and SLAPSHOT , a Python proxy that tunnels traffic from the gateway into the internal network. Together they provide stealthy command execution, persistent root access, and a path toward internal credentials.
Background
The campaign was identified in late September 2026, with exploitation traced back to at least early September. The reporting does not attribute it to a named threat group. What is known is that the actors use two custom tools not seen before: WHIPSHOT, which serves as the remote command channel on the appliance, and SLAPSHOT, which extends the actors' reach from the gateway into the internal network.
Victims span government, financial services, education, and legal services organizations in North America and Europe . The article does not give a victim count. In one confirmed intrusion, the actors used the SLAPSHOT tunnel from an internet-facing gateway to explore the internal network and search for credentials, showing that the appliance serves as a pivot point, not just an entry point.
Vulnerability Details
| CVE ID | CVSS Score | EPSS Score | Affected Products |
|---|---|---|---|
| CVE-2026-88772 | 9.5 (Critical) | 1.30% | NetScaler ADC and Gateway 14.1 prior to 14.1-73.37; 13.1 prior to 13.1-64.23; NetScaler ADC FIPS prior to 14.1-73.37 FIPS; NetScaler ADC FIPS and NDcPP prior to 13.1-37.279. |
| CVE-2026-88771 | 9.5 (Critical) | 1.06% | NetScaler ADC and Gateway 14.1 prior to 14.1-73.37; 13.1 prior to 13.1-64.23; NetScaler ADC FIPS prior to 14.1-73.37 FIPS; NetScaler ADC FIPS and NDcPP prior to 13.1-37.279. |
Attack Methodology
- 1. Pre-authentication exploitation. The attacker sends a crafted or fragmented DTLS record header during the first handshake. The malformed header corrupts heap memory in the packet engine and diverts control flow to shellcode running as root on FreeBSD, with no credentials needed.
-
2. Web shell self-installation.
The initial payload edits the appliance's
httpd.confso that non-script file types execute as PHP. Some intrusions used.debfiles; a stealthier variant used.sigfiles plus a redirect so a request for an.icoicon is served by the hidden PHP shell. -
3. Root persistence.
The installer sets the setuid bit on
/bin/shso commands issued through the web shell keep running as root, then forces a full appliance reboot so the changes survive. - 4. WHIPSHOT command channel. The PHP web shell, disguised as a Debian package, reads Base64-encoded commands from sequential HTTP header fields and relays them over a local loopback connection. It suppresses its own error reporting and always answers with a 404.
- 5. SLAPSHOT tunneling. A Python proxy opens a local port and forwards TCP traffic into the internal network. It closes idle sessions after 15 minutes, exits after 10 minutes without activity, and removes its port and lock files on shutdown.
- 6. Internal exploration. In one confirmed intrusion, the actor used the tunnel from an internet-facing gateway to explore the internal network and search for credentials.
Indicators of Compromise (IOCs)
● Request path:
/vpn/media/e6ee7c85.ico
(served by
e6ee7c85.sig)
● Modified httpd.conf entries mapping .deb or .sig files to PHP execution, plus a redirect from an
.ico request to a
.sig file
● Web requests returning a normal-looking 404 with unusually long processing time
● /bin/sh with the setuid bit set, followed by an unplanned appliance reboot
● Local proxy port and lock files created by SLAPSHOT, removed after 10 minutes of inactivity
MITRE ATT&CK Mapping
| Technique ID | Technique Name | Tactic |
|---|---|---|
| T1190 | Exploit Public-Facing Application | Initial Access |
| T1505.003 | Server Software Component: Web Shell | Persistence |
| T1548.001 | Abuse Elevation Control Mechanism: Setuid and Setgid | Privilege Escalation |
| T1036.008 | Masquerading: Masquerade File Type | Defense Evasion |
| T1070.004 | Indicator Removal: File Deletion | Defense Evasion |
Visual Attack Flow
Mitigation
- 1. Patch first. Upgrade NetScaler ADC and Gateway to 14.1-73.37 or later, or 13.1-64.23 or later; NetScaler ADC FIPS to 14.1-73.37 FIPS or later; NetScaler ADC FIPS and NDcPP to 13.1-37.279 or later. Both CVEs share these fixed builds (Citrix advisory CTX697096).
- 2. Apply the interim DTLS control only if patching is delayed. Disable DTLS and block inbound UDP/443 to close the CVE-2026-88772 path. This does not cover CVE-2026-88771.
-
3. Audit web server configuration and content.
Review
httpd.conffor.debor.sigfiles handled as PHP, inspect/vpn/media/, and flag slow 404 responses. -
4. Check privilege state.
Verify
/bin/shdoes not carry the setuid bit and investigate unexplained appliance reboots. - 5. Watch for tunneled internal activity. Review traffic that originates from the gateway toward internal hosts, since SLAPSHOT forwards TCP from a local port on the appliance.
Instantly Fix Risks with Saner Patch Management
Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.
It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.
Experience the fastest and most accurate patching software here.




