Particle.news

Citrix NetScaler Zero-Days Used to Gain Root Access on Internet-Facing Appliances

Researchers warn that available patches do not evict attackers or stop stolen credentials from being abused.

Overview

  • Security firms Mandiant and Google Threat Intelligence Group say exploitation began in early September and persisted undetected for weeks before public disclosure and patches.
  • One flaw, CVE-2026-88772, is a DTLS memory overflow in NetScaler’s packet engine that can be triggered before login to run arbitrary shellcode with root privileges.
  • After gaining root, attackers modified the appliance web server to run disguised PHP shells and set /bin/sh to keep root-level access across reboots.
  • Mandiant and GTIG identified new post-exploit tools called WHIPSHOT, a PHP web shell that hides commands in HTTP headers, and SLAPSHOT, a Python tunneler that proxies traffic into internal networks.
  • Citrix has released fixes and national CERTs have issued hunt and containment guidance, but responders say organizations must preserve logs and memory before updating, assume credential theft, rotate secrets after remediation, and consider disabling DTLS or blocking UDP/443 as temporary mitigations.