---
title: Actively Exploited Zero-Day Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway Used to Deploy Web Shells
description: Citrix has released security updates for two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway that threat actors exploited in the wild before patches were available.
---

[Skip to content](https://1898advisories.burnsmcd.com/actively-exploited-zero-day-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway-used-to-deploy-web-shells#main-content)

![1898-logo-grey-R-1](https://1898advisories.burnsmcd.com/hs-fs/hubfs/1898-logo-grey-R-1.webp?width=188&height=100&name=1898-logo-grey-R-1.webp)

- [Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)
- [Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)
- [View All](https://1898advisories.burnsmcd.com/)

Open main navigation

Close main navigation

- [Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)
- [Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)
- [View All](https://1898advisories.burnsmcd.com/)
- [Contact us](https://1898andco.burnsmcd.com/contact-us)

[Contact us](https://1898andco.burnsmcd.com/contact-us)

 October 2, 2026

# Actively Exploited Zero-Day Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway Used to Deploy Web Shells

![Picture of The 1898 & Co. Team](https://1898advisories.burnsmcd.com/hs-fs/hubfs/1898%20Cyberthreat%20Advisory%20Blog%20Assets/1898-Co-Ampersand.png?width=50&name=1898-Co-Ampersand.png) [The 1898 & Co. Team](https://1898advisories.burnsmcd.com/author/1898-co-team)

#### Security Advisory Brief

Citrix has released security updates for two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway that threat actors exploited in the wild before patches were available. Google Threat Intelligence Group and Mandiant report that the campaign has been active since at least early September 2026 and has targeted government, financial services, education, legal services, and professional services organizations across North America and Europe. CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on September 27, 2026, the same day Citrix published bulletin CTX697096, and set a federal remediation deadline of September 30, 2026.

CVE-2026-88771, with a CVSS v4.0 score of 9.5, is an improper input validation flaw that allows an unauthenticated remote attacker to execute arbitrary commands on the appliance, and it applies to every deployment without any special feature enabled. CVE-2026-88772, also with a CVSS v4.0 score of 9.5, is a memory overflow in DTLS handshake processing that can produce remote code execution or a denial of service on appliances that have DTLS enabled on VPN virtual servers, a setting that is on by default. Following exploitation, the operators gained root access, modified the appliance web server configuration so that ordinary-looking package files execute as PHP, deployed a custom PHP web shell tracked as WHIPSHOT and a Python tunneler tracked as SLAPSHOT, and set the setuid bit on the system shell to retain root privileges.

The risk is elevated because NetScaler Gateway sits at the network edge and brokers remote access, authentication, and TLS termination for the organization. A compromised appliance exposes the administrative accounts, SSH keys, TLS private keys, and LDAP or RADIUS service credentials it handles, and the SLAPSHOT tunneler gives the operators a path into internal networks. Applying the update closes the vulnerabilities but does not remove web shells or backdoors already planted, so organizations must treat patching and compromise assessment as separate and equally urgent tasks.

#### Threats and Vulnerabilities

CVE-2026-88771, with a CVSS v4.0 score of 9.5 assigned by Citrix and a CVSS v3.1 score of 9.8 assigned by NIST, is an improper input validation weakness (CWE-20) in NetScaler ADC and NetScaler Gateway that lets an unauthenticated remote attacker execute arbitrary commands. Unlike many NetScaler flaws, it does not depend on a Gateway or AAA virtual server or any optional feature, so every unpatched appliance reachable by an attacker is in scope. Affected releases are NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, NetScaler ADC 14.1-FIPS before 14.1-73.37, and NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279. Citrix reported in-the-wild exploitation of this flaw, and CISA lists it in the Known Exploited Vulnerabilities catalog. Mandiant notes that disabling DTLS does not mitigate this vulnerability, which leaves patching as the only remediation.

CVE-2026-88772, with a CVSS v4.0 score of 9.5 assigned by Citrix and a CVSS v3.1 score of 8.1 assigned by NIST, is a memory overflow weakness (CWE-119) triggered during the DTLS handshake before any authentication takes place. Successful exploitation can produce remote code execution or a denial of service, and Mandiant observed it crashing the NetScaler Packet Processing Engine to establish initial root-level access. The flaw requires DTLS to be enabled on a VPN virtual server, which is the default configuration for NetScaler Gateway deployments. It affects the same version ranges as CVE-2026-88771 and is likewise listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation leaves characteristic log artifacts, including SSL handshake failures on DTLSv1.0 with the reason "Handshake failure-Internal Error" followed by packet engine crash and watchdog messages.

The post-exploitation toolkit observed in this campaign is built for stealth and persistence on the appliance. Operators modified the Apache httpd.conf file so that files with .deb or .sig extensions under the VPN scripts path execute as PHP, and then planted the WHIPSHOT web shell, which reads Base64-encoded commands from sequential HTTP headers, suppresses error output, and returns spoofed 404 responses to minimize log evidence. The SLAPSHOT Python tunneler binds to a loopback port, records that port in a hidden file under /tmp, and proxies operator traffic into the internal network for reconnaissance and credential theft before deleting its working files when idle. Operators also made /bin/sh setuid root and forced an appliance reboot, so these changes can survive a version upgrade. Google Threat Intelligence Group attributes the activity to a suspected state-backed group.

Citrix bulletin CTX697096 also addresses six additional NetScaler vulnerabilities, CVE-2026-88773 through CVE-2026-88778, which carry CVSS scores ranging from 7.0 to 8.8 and depend on specific load balancing, virtual server, Gateway, or TCP service configurations. There is no reported exploitation of these six flaws at this time. Because they are fixed by the same release, organizations that apply the update for the two zero-days remediate them at the same time.

#### Client Impact

A compromised NetScaler appliance gives an attacker a privileged foothold at the network edge, with direct visibility into remote-access sessions, authentication traffic, and decrypted TLS flows. Exposure of LDAP and RADIUS service-account credentials, TLS private keys, and administrator passwords can allow the attacker to impersonate users, decrypt or intercept traffic, and move into internal systems through the SLAPSHOT tunnel. For organizations that rely on NetScaler Gateway for remote access to operational technology or engineering networks, an edge compromise can provide a route toward supervisory and control systems that are otherwise segmented from the internet. Exploitation of CVE-2026-88772 can also crash the packet engine and cause an outage of remote access and load-balanced services.

From a compliance perspective, federal civilian agencies were directed to remediate both vulnerabilities under CISA's Known Exploited Vulnerabilities requirements by September 30, 2026, and many regulators and auditors treat KEV listing as a benchmark for timely patching in the private sector. Organizations subject to NERC CIP, TSA security directives, HIPAA, PCI DSS, or state data-breach laws should assess whether credential or data exposure through a compromised appliance triggers incident reporting obligations. Because patching does not remove existing implants, documenting a compromise assessment for each appliance will be important evidence of due diligence. Unremediated edge devices that later serve as an entry point for a breach can increase regulatory scrutiny and liability exposure.

#### Mitigations

Organizations operating Citrix NetScaler ADC or NetScaler Gateway should take the following actions immediately.

Upgrade every NetScaler ADC and NetScaler Gateway appliance to 14.1-73.37 or later or 13.1-64.23 or later, FIPS builds to 14.1-73.37 or later, and 13.1-FIPS and 13.1-NDcPP builds to 13.1-37.279 or later, as listed in Citrix bulletin CTX697096; treat any appliance on an end-of-life release as compromised-at-risk and replace or upgrade it.

Before and after upgrading, perform a compromise assessment on each appliance: review httpd.conf for AddHandler, AddType, or similar directives that execute .deb, .sig, .tgz, or .rpm files as PHP, inspect the /vpn/scripts/linux and /vpn/media paths for unexpected files, check whether /bin/sh carries the setuid bit, and look for hidden files such as /tmp/.uxdport, /tmp/.uxdlock, and /var/tmp/.nsmon.

Search NetScaler logs for SSL\_HANDSHAKE\_FAILURE entries on DTLSv1.0 with the reason "Handshake failure-Internal Error" and for packet engine crash or watchdog messages, and review crontab entries and listening ports for unexplained persistence or tunneling.

If an appliance cannot be upgraded immediately, disable DTLS on VPN virtual servers where operationally feasible and block inbound UDP/443 upstream to reduce exposure to CVE-2026-88772, while recognizing that this does not mitigate CVE-2026-88771 and restricting management interface access to trusted networks.

If any indicator of compromise is found, isolate the appliance, rebuild it from a clean image rather than relying on an in-place upgrade, and rotate every credential and key it handled, including administrator passwords, LDAP and RADIUS service-account credentials, SSH keys, and TLS certificates, then hunt for lateral movement from the appliance into internal networks.

Because patching closes the entry point but does not evict an attacker already present, organizations should complete both remediation and compromise assessment for every NetScaler appliance and retain the results as part of their incident response records.

#### 1898 & Co. Response

1898 & Co. works with critical infrastructure and enterprise organizations to assess and harden internet-facing remote-access and edge infrastructure, including application delivery controllers and VPN gateways that bridge corporate and operational networks. Our team can help clients inventory exposed NetScaler appliances, confirm patch levels against the fixed releases in Citrix bulletin CTX697096, and prioritize remediation based on network position and the systems each appliance protects. We also help clients evaluate whether remote-access paths into OT environments are appropriately segmented and monitored.

Our incident response and threat hunting practitioners can perform compromise assessments on NetScaler appliances, reviewing web server configuration, file system artifacts, packet engine crash logs, and persistence mechanisms associated with the WHIPSHOT and SLAPSHOT tooling. Where indicators are found, 1898 & Co. supports appliance rebuild planning, credential and certificate rotation, and investigation of lateral movement from the edge into internal and operational networks. This work is informed by our experience responding to edge-device compromises across the energy, water, manufacturing, and public sector.

Beyond immediate response, 1898 & Co. helps organizations build durable processes for tracking known exploited vulnerabilities, monitoring edge infrastructure, and meeting regulatory reporting obligations under frameworks such as NERC CIP and TSA security directives. We assist clients in developing detection content for their security monitoring platforms and in rehearsing response to edge-device compromise through tabletop exercises. Clients seeking support with this advisory can contact their 1898 & Co. representative.

#### Sources

1. [Citrix Security Bulletin CTX697096 — NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778](https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096)
2. [CISA Known Exploited Vulnerabilities Catalog — CVE-2026-88771](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771)
3. [CISA Known Exploited Vulnerabilities Catalog — CVE-2026-88772](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772)
4. [NVD Entry — CVE-2026-88771](https://nvd.nist.gov/vuln/detail/CVE-2026-88771)
5. [NVD Entry — CVE-2026-88772](https://nvd.nist.gov/vuln/detail/CVE-2026-88772)
6. [NVD Entry — CVE-2026-88773](https://nvd.nist.gov/vuln/detail/CVE-2026-88773)
7. [NVD Entry — CVE-2026-88774](https://nvd.nist.gov/vuln/detail/CVE-2026-88774)
8. [NVD Entry — CVE-2026-88775](https://nvd.nist.gov/vuln/detail/CVE-2026-88775)
9. [NVD Entry — CVE-2026-88776](https://nvd.nist.gov/vuln/detail/CVE-2026-88776)
10. [NVD Entry — CVE-2026-88777](https://nvd.nist.gov/vuln/detail/CVE-2026-88777)
11. [NVD Entry — CVE-2026-88778](https://nvd.nist.gov/vuln/detail/CVE-2026-88778)
12. [MITRE ATT&CK — T1505.003 Server Software Component: Web Shell](https://attack.mitre.org/techniques/T1505/003/)

[Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)

*The information in this cybersecurity advisory is provided "as is" for informational purposes only. 1898 & Co. does not provide any warranties or guarantees of any kind regarding this information. You assume all risks if you choose to rely on this information. In no event shall 1898 & Co. or its contractors or subcontractors be liable for any damages including, but not limited to, direct, indirect, special or consequential damages, arising out of, resulting from, or in any way connected with, this information, whether or not based upon warranty, contract, tort, or otherwise, whether or not arising out of negligence, and whether or not injury was sustained from, or arose out of the results of, or reliance upon the information*

*1898 & Co. does not endorse any product or service, except as expressly stated otherwise. Any reference to products or processes does not constitute or imply 1898 & Co.’s endorsement or recommendation.*

Subscribe

✕ Close

 

[Accessibility](https://1898andco.burnsmcd.com/accessibility)  |  [Privacy Statement](https://1898andco.burnsmcd.com/privacy)

© 2026 1898 & Co., a part of Burns & McDonnell. All Rights Reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "The 1898 & Co. Team",
    "url" : "https://1898advisories.burnsmcd.com/author/1898-co-team"
  },
  "dateModified" : "2026-10-02T17:20:35.412Z",
  "datePublished" : "2026-10-02T17:20:35.000Z",
  "headline" : "Actively Exploited Zero-Day Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway Used to Deploy Web Shells",
  "mainEntityOfPage" : {
    "@id" : "https://1898advisories.burnsmcd.com/actively-exploited-zero-day-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway-used-to-deploy-web-shells",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "//cdn2.hubspot.net/hub/477837/file-2585615236-jpg/Logo_1_Primary_2Color1.jpg"
    },
    "name" : "Burns & McDonnell Engineering Co"
  }
}
```