Overview
- Researchers found exploitation began in early September, with the earliest known successful trigger dated Sept. 3, and activity surged into mass scanning and exploitation in late September.
- The primary flaw, CVE-2026-88772, is a DTLS packet‑processing heap overflow that can be triggered during the initial handshake to run arbitrary code as root on the FreeBSD host.
- After initial root access attackers edited Apache configs to run deceptive files as PHP and installed novel tools named WHIPSHOT (a PHP web shell) and SLAPSHOT (a Python tunneler) to proxy into internal networks.
- Citrix released patches on Sept. 27 and CISA ordered rapid remediation, but researchers warn many internet‑exposed NetScaler appliances remain at risk and that patching does not remove existing attacker access or stolen credentials.
- Responders advise preserving memory and logs before updating, disabling DTLS or blocking inbound UDP/443 where feasible as a temporary mitigation, and rotating all keys, certificates and credentials after systems are secured.