Attackers are exploiting two Citrix NetScaler zero-day vulnerabilities to gain root access, install web shells and tunneling malware, steal credentials, and move into internal networks.
Mandiant said the attacks began at least as early as September and affected organizations in North America and Europe, including government, financial, education, legal, and professional services organizations. Citrix has confirmed that both vulnerabilities were exploited against unpatched NetScaler deployments and has released security updates.
The vulnerabilities are tracked as CVE-2026-88771 and CVE-2026-88772. The first is an unauthenticated remote code execution flaw affecting NetScaler ADC and Gateway deployments. The second is a memory overflow vulnerability that can enable remote code execution or denial of service when DTLS is enabled.
Researchers say the attacks can exploit the NetScaler Packet Processing Engine (NSPPE) and result in root-level access on the underlying FreeBSD system. Mandiant believes specially malformed or fragmented network records can trigger heap memory corruption and allow attackers to execute shellcode.
After gaining access, attackers installed custom PHP web shells and changed NetScaler's web-server configuration so files that normally appear to be CSS, image, or package files could execute PHP code.
GreyNoise previously observed an attacker attempting to modify /bin/sh to provide a root shell and installing a password-protected web shell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver.
Mandiant also found two previously undocumented malware families called WHIPSHOT and SLAPSHOT. The first one acts as a PHP web shell and HTTP proxy, while the latter is a Python-based TCP tunneling tool. When combined, they can allow attackers to connect from a compromised NetScaler appliance to internal systems.
In at least one intrusion, Mandiant said attackers used the tunnel for network reconnaissance and credential theft. The malware can also stop itself after periods of inactivity, which can make detection more difficult.
Attackers also modified /bin/sh permissions to maintain root-level execution. Mandiant said threat actors used the Unix setuid permission so commands launched by their web shells could continue running with elevated privileges.
Security teams are being advised to install the latest Citrix updates and inspect NetScaler appliances for signs of compromise. Potential indicators include unauthorized PHP handlers in /etc/httpd.conf, suspicious .deb or .sig files containing PHP code, unexpected NSPPE crashes, unusual HTTP 404 responses, and files such as /tmp/.uxdport and /tmp/.uxdlock.
Defenders should also check whether /bin/sh has unexpected setuid-root permissions and look for suspicious Python processes, particularly launched with nohup or containing Base64-encoded payloads.