Newly Patched NetScaler Flaw Already Under Active Attack, Root Access Exploited
Security researchers at Mandiant Consulting and Google Threat Intelligence Group have observed attackers exploiting a newly patched flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, targeting organisations across North America and Europe. Victims span government, financial services, technology, education, and legal and professional services sectors, with dozens of organisations already affected as of September 2026.
The vulnerability, tracked as CVE-2026-88772, allows attackers to bypass authentication and crash a core NetScaler processing component to gain root-level access without needing valid credentials. Once inside, attackers deploy a previously unseen PHP web shell called WHIPSHOT, which hides its commands inside normal-looking web traffic, alongside a tool named SLAPSHOT that tunnels traffic into internal networks to support reconnaissance and credential theft. In at least one confirmed case, attackers used this access to manually explore internal systems and steal credentials.
Mandiant has warned that broader, opportunistic exploitation of this flaw (and a related one, CVE-2026-88771) is likely in the near term as more threat actors adopt the technique. Because the flaw affects internet-facing appliances used for remote access, unpatched systems present an attractive and highly exposed target.
Key Takeaway: If your business uses Citrix NetScaler ADC or Gateway appliances, apply the latest security patches immediately and check for signs of compromise, as attackers are actively exploiting this flaw right now.