3 min Security

Google: Citrix vulnerability has been exploited since early September

Google: Citrix vulnerability has been exploited since early September

Mandiant and the Google Threat Intelligence Group report that the recently discovered vulnerability in Citrix NetScaler ADC and Gateway has been exploited since early this month. Victims are located in Europe and North America. Attackers are using the WHIPSHOT and SLAPSHOT malware families to gain access.

The vulnerability in question is CVE-2026-88772. Citrix has already patched this flaw, but it did not prevent victims from being affected. Organizations in the government, financial, tech, education, and legal and business services sectors have been impacted. According to Citrix, a second zero-day vulnerability, CVE-2026-88771, is also being exploited.

This second bug is a critical RCE vulnerability that allows unauthenticated attackers to execute commands, with even default configurations being vulnerable to it, SecurityWeek reports. The attacks are largely uncoordinated and thus appear to rely on automated scans. After a root-cause analysis and proof-of-concept for CVE-2026-88771 were made public, the exploitation escalated into massive attacks, Help Net Security reports. CISA instructed U.S. federal agencies to apply patches immediately.

See also: New Citrix vulnerability affects hospitals and government

Gaining access via DTLS

CVE-2026-88772 is a flaw in the NetScaler Packet Processing Engine (NSPPE). During the DTLS handshake, even before authentication, the NSPPE processes incoming records. GTIG does not have exploit code itself, but telemetry suggests that manipulated or fragmented headers cause what is known as heap corruption. As a result, arbitrary shellcode with root privileges can be executed on the underlying FreeBSD platform. The exploit enters via UDP/443.

The attackers then modify httpd.conf so that files with extensions such as .deb or .sig run as PHP scripts, according to the Google researchers. In one variant, requests for .ico files under /vpn/media/ are redirected to a webshell. The webshell neatly returns a 404 error, but the payload is still delivered. To maintain root privileges, the attackers set the setuid bit on /bin/sh.

Whipshot and Slapshot

The payloads are typically WHIPSHOT or SLAPSHOT. WHIPSHOT is a PHP webshell that hides Base64-encoded C&C payloads in HTTP headers. SLAPSHOT is a Python tunneler that routes traffic into the internal network. In at least one case, the attacker used that proxy to conduct manual reconnaissance and steal login credentials. SLAPSHOT is harder to detect than many other types of malware because it self-deletes after ten minutes of inactivity.

According to GTIG, vulnerabilities in edge devices accounted for about half of enterprise-related zero-days in 2025. Such devices fall outside the scope of EDR tools, despite having internet access.

Patching and rotating credentials

Google’s security researchers, like other parties, strongly recommend upgrading to NetScaler 14.1-73.37 or 13.1-64.23 (or later). Those who cannot patch immediately can disable DTLS and block incoming UDP/443 traffic upstream. However, this only protects against CVE-2026-88772 and not CVE-2026-88771. Organizations must also assume that credentials on a compromised appliance have been leaked. Mandiant recommends revoking sessions and rotating administrator passwords, SSH keys, and TLS certificates.