NetScaler Intrusions Turn a Gateway Flaw Into Root-Level Network Access

Mandiant links CVE-2026-88772 to NetScaler attacks granting root access, web shells, and internal network tunnels across dozens of orgs.

NetScaler Intrusions Turn a Gateway Flaw Into Root-Level Network Access
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 11 min

Mandiant traced the campaign to CVE-2026-88772

Attackers exploited a Citrix NetScaler vulnerability to obtain root access, implant web shells, and establish tunnels into organizations’ internal networks.

Google’s Mandiant and Threat Intelligence Group observed the attacks in late September. Their investigation indicated that the campaign had been operating since at least early September and focused specifically on exploitation of CVE-2026-88772.

Citrix also patched a second NetScaler vulnerability, CVE-2026-88771, over the weekend, according to SecurityWeek’s reporting. The report does not provide the patch publication date or fixed-build numbers for every supported branch.

Both flaws affect NetScaler ADC and NetScaler Gateway. However, the available evidence does not establish that the campaign investigated by Mandiant exploited both vulnerabilities. Mandiant CTO Charles Carmakal instead warned that multiple actors were expected to begin broad, opportunistic exploitation of both CVEs in the near term.

GreyNoise separately observed zero-day exploitation attempts on September 24, several days before disclosure and patching. Its reporting describes the attackers’ commands and persistence method but does not connect those attempts to Mandiant’s campaign or identify which of the two CVEs was used.

The vulnerabilities enable command execution, RCE, or disruption

CVE-2026-88771 is an improper input-validation vulnerability categorized as CWE-20. NVD assigns it a CVSS v3 score of 9.8 with the vector:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The vulnerability is network-accessible, requires no privileges or user interaction, and has low attack complexity. Successful exploitation can allow an unauthenticated attacker to execute arbitrary commands.

CVE-2026-88772 is classified as CWE-119, covering insufficient restrictions on operations within a memory buffer. Its CVSS v3 score is 8.1, with the vector:

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

This flaw also requires neither authentication nor user interaction, although its attack complexity is rated high. NVD identifies remote code execution and denial of service as possible outcomes.

SecurityWeek describes both vulnerabilities as critical and reports that they can enable unauthenticated remote code execution. The detailed campaign findings, including root compromise and malware deployment, are tied by Mandiant and GTIG to CVE-2026-88772.

Standard, FIPS, and NDcPP builds are affected

The NVD product summaries list NetScaler Application Delivery Controller and NetScaler Gateway versions below 13.1-64.23 as affected. The detailed descriptions identify additional branches and certified editions.

Affected NetScaler ADC ranges are:

  • Versions before 14.1-73.37
  • Versions before 13.1-64.23
  • Versions before 14.1-73.37 FIPS
  • Versions before 13.1.37.279 FIPS and NDcPP

Affected NetScaler Gateway ranges are:

  • Versions before 14.1-73.37
  • Versions before 13.1-64.23

Administrators can use these thresholds to locate potentially vulnerable systems, including FIPS and NDcPP deployments. They should still verify the appropriate remediation for each appliance and branch against Citrix’s instructions rather than treating the NVD ranges as a complete patching guide.

Before updates became available, government cybersecurity agencies and security firms advised operators to disconnect affected NetScaler appliances from the internet while zero-day investigations continued.

WHIPSHOT and SLAPSHOT opened a route into internal networks

In the activity investigated by Mandiant, attackers used CVE-2026-88772 to gain root access to NetScaler ADC and Gateway appliances. They modified the appliances’ web-server configuration and installed web shells that executed with root privileges.

Investigators identified two previously unseen tools:

  • WHIPSHOT, a PHP web shell.
  • SLAPSHOT, a Python-based tunneling tool.

Together, the tools provided a path from the compromised edge appliance into the victim’s internal environment. Mandiant said the access supported reconnaissance, lateral movement, and credential theft.

In at least one intrusion, an operator manually explored the internal network through the tunnel and stole credentials. Investigators also found indications that the threat actor might have been administering similar web shells across several compromised environments. That observation does not identify a specific group.

In its separate observations, GreyNoise saw exploitation attempts that tried to set the setuid and setgid bits on /bin/sh to obtain a root shell. The activity then installed a password-protected web shell that received attacker communications through a cookie value. GreyNoise assessed that the method might be intended to prevent commands from persisting in web logs.

Victim estimates exceed dozens, while exposure was far larger

The Mandiant investigation indicates that organizations in North America and Europe were likely affected. The targeted sectors included government, financial services, education, legal services, and professional services.

Carmakal said dozens of organizations had been hit, including during activity involving suspected state-sponsored threat actors. Separately, Kevin Beaumont reported awareness of more than 100 victim organizations as of Tuesday and assessed that the activity appeared to be an espionage campaign.

These are independent estimates and have not been reconciled. The reporting also does not attribute the entire activity set to a named threat actor.

Palo Alto Networks estimated that approximately 50,000 NetScaler instances were potentially exposed as of September 27. That number measures possible exposure rather than confirmed compromise.

WatchTowr, described as one of the first security firms to confirm exploitation in the wild, published technical details for both vulnerabilities. Publication of research, combined with the number of exposed appliances, supports Mandiant’s expectation that more actors will attempt to exploit the flaws. It does not show that both CVEs were used in the campaign already investigated.

CISA deadlines have passed, but patching must include triage

CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog on 2026-09-27. The remediation deadline for U.S. federal agencies was 2026-09-30.

For both vulnerabilities, CISA requires vendor-directed mitigations consistent with BOD 26-04, along with its Forensics Triage Requirements. Agencies must assess each asset’s internet exposure and follow the directive’s risk-based patching guidance.

Applicable BOD 26-04 guidance also covers cloud services. Where mitigations are unavailable, CISA directs agencies to discontinue use of the affected product.

NetScaler operators should now:

  1. Inventory ADC and Gateway appliances within the affected version ranges.
  2. Apply the Citrix-prescribed update or mitigation for each installed branch.
  3. Determine whether each appliance was internet-accessible before remediation.
  4. Review web-server configuration for unauthorized changes.
  5. Search for WHIPSHOT, SLAPSHOT, unexpected web shells, and unauthorized tunnels.
  6. Check /bin/sh for unexplained setuid or setgid permission changes.
  7. Investigate internal reconnaissance, lateral movement, or credential access originating from NetScaler systems.

Systems exposed before patching warrant forensic review because the observed activity included root-level web shells and configuration changes. Installing an update does not itself remove an implant that was already placed on an appliance.

The NetScaler entries also continue a recent series affecting Citrix and Microsoft. Over the preceding 90 days, CISA added CVE-2026-19490 on 2026-09-09; CVE-2026-81963 and CVE-2026-85880 on 2026-09-08; CVE-2026-8452 and CVE-2019-1068 on 2026-08-26; and CVE-2026-33824 on 2026-08-18 for the same vendors.

The SharePoint KEV entry is unrelated to this campaign

A separate report references CVE-2026-65660, a Microsoft Office SharePoint code-injection vulnerability. The supplied information does not connect it to the NetScaler intrusions.

CVE-2026-65660 allows an authorized attacker to execute code over a network. It affects Microsoft SharePoint Server versions before 16.0.19725.20522 and carries a CVSS v3 score of 8.8.

CISA added the SharePoint flaw to KEV on 2026-09-25, setting a federal remediation deadline of 2026-09-28. Its required action likewise calls for vendor-directed mitigations, BOD 26-04 compliance, forensic triage, evaluation of internet exposure, and discontinuation if mitigations are unavailable.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →