Particle.news

Active Exploitation of Two Citrix NetScaler Zero-Days Gives Attackers Root Access

Citrix issued patches on Sept. 27; however implants and novel tunneling tools mean organizations must preserve memory and logs and treat gateway credentials as likely exposed.

Overview

  • Security firms Mandiant and Google Threat Intelligence Group say attackers began exploiting NetScaler flaws in early September and remained undetected for weeks, allowing broad access to internet-facing appliances.
  • Two critical bugs are confirmed exploited: CVE-2026-88772 is a DTLS-related heap overflow in the NetScaler packet engine that can run shellcode before login, and CVE-2026-88771 allows unauthenticated command execution on default configurations.
  • Researchers observed post-exploitation tooling and persistence techniques including WHIPSHOT (a PHP web shell), SLAPSHOT (a Python tunneler), Apache config changes that run .deb/.sig as PHP, .ico-to-.sig redirects, and making /bin/sh setuid to keep root access.
  • Citrix released fixed builds on Sept. 27 and national CERTs (CISA, NCSC-NL, ACSC) urge urgent patching plus forensic steps: capture memory and logs before upgrades, inventory customer-managed versus Citrix-managed instances, disable DTLS or block inbound UDP/443 where feasible, and rotate keys and credentials after mitigation.
  • Dozens to more than 100 organizations across government, finance, education, telecom and professional services report likely impact, and defenders should assume compromise, expect follow-on opportunistic abuse, and prepare for both credential theft and possible VPN outages from denial-of-service exploitation.