Zero-Day Attacks Hitting Citrix NetScaler Devices: What Businesses Need to Know
Security researchers at Mandiant and Google Threat Intelligence Group have confirmed active exploitation of a zero-day vulnerability, CVE-2026-88772, affecting Citrix NetScaler ADC and NetScaler Gateway appliances. The attacks have been running since at least early September 2026, with organisations in government, financial services, education, and legal sectors across North America and Europe likely affected. A second vulnerability, CVE-2026-88771, is also reportedly being exploited by attackers.
The flaw allows attackers to bypass authentication entirely and crash a core appliance process to gain full, root-level control of the device. Once inside, attackers have deployed custom hacking tools, including a hidden web shell called WHIPSHOT that hides its commands inside normal-looking web traffic, and a tool called SLAPSHOT that lets attackers tunnel into internal networks to snoop around and steal login credentials.
Citrix has released patches and guidance for affected customers. Security teams can also look for specific warning signs in device logs, including SSL handshake failures and unexpected crashes of the appliance's core processing engine, which may indicate an exploitation attempt has occurred.