Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Unknown threat actors have been observed to take advantage of a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target businesses in North America and Europe.

According to Mandiant Consulting and Google Threat Intelligence Group (GTIG)’s observation in September 2026, the attack has targeted government, financial services, technology, education, and legal and professional services sectors.

In a post published on LinkedIn, Charles Carmakal, chief technology officer at Mandiant Consulting, mentioned that the targeted intrusions affected dozens of organizations, noting that there is a broad and opportunistic exploitation of CVE-2026-88772 and CVE-2026-88771 by various threat actors in the near term.

Exploitation of CVE-2026-88772 allows attackers to bypass authentication and trigger an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access, the tech giant said.

The attacks have been observed weaponizing the vulnerability to deploy a post-exploitation toolkit that includes previously unreported PHP web shells, like WHIPSHOT, that are capable of disguising Base64-encoded command-and-control (C2) payloads within native HTTP headers read more about Attackers Exploit NetScaler Flaw for Root Access Deploy WHIPSHOT and SLAPSHOT.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *