Federal NetScaler clock ends today. Mandiant just published the web shells to hunt

By George Bailey   Published: 09/30/26   4 min read

CISA’s federal remediation date for the two exploited NetScaler remote code execution flaws is Wednesday, Sep 30, 2026. Mandiant’s new write-up, covered by BleepingComputer on Sep 29, shows what operators who only “scheduled the patch” are missing: custom web shells, httpd.conf tricks that make images and CSS execute as PHP, and a Python tunnel Mandiant calls SLAPSHOT.

If the appliance is still on a vulnerable build, patch first. If it was Internet-facing before Saturday’s fix, hunt before you declare the ticket closed.

A patched NetScaler with setuid /bin/sh and a fake 404 web shell is not a closed ticket.

What happened

Citrix disclosed CVE-2026-88771 and CVE-2026-88772 on Sep 27 (bulletin CTX697096) after national CERTs and suppliers privately warned customers over the weekend. Both flaws enable unauthenticated remote code execution. CISA added them to KEV the same day with a Sep 30 due date. Monday’s brief covered the patch itself; today’s story is the post-exploitation picture Mandiant published afterward.

Mandiant says exploitation of CVE-2026-88772 bypasses authentication, crashes the NetScaler Packet Processing Engine, and yields root on the FreeBSD appliance. Attackers installed PHP web shells and rewrote /etc/httpd.conf so non-executable extensions (.deb, .sig, .ico under /vpn/media/, CSS-looking paths) executed as PHP. Some shells returned fake HTTP 404 responses while running commands.

Two previously undocumented malware families appear in the report. WHIPSHOT is a PHP web shell disguised as a Debian package in the VPN scripts directory. It proxies to SLAPSHOT, a Python TCP tunnel that bridges the appliance to internal hosts for credential theft and recon. Attackers also set the setuid bit on /bin/sh so web shell commands kept root. GreyNoise earlier observed similar staging, including a password-protected shell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver. Mandiant links observed malware to CVE-2026-88772; Citrix says CVE-2026-88771 has been exploited too. Disabling DTLS only helps against 88772.

Why it matters

Edge ADCs and Gateways are still the shortest path into a lot of networks, and they rarely run the same EDR stack as a laptop. Federal agencies hit the BOD clock today; everyone else should treat that date as the outer bound, not a suggestion.

The Mandiant detail changes the definition of done. Installing 14.1-73.37 or 13.1-64.23 closes the bug. It does not remove WHIPSHOT, SLAPSHOT, setuid shells, or httpd aliases already planted.

What to do first

Forward this

If your team runs Citrix NetScaler ADC or Gateway: today’s federal due date is the reminder to finish the upgrade, then ask whether anyone hunted for Mandiant’s WHIPSHOT/SLAPSHOT web shells and a setuid /bin/sh. A patched box can still be an attacker’s tunnel. Ask for a yes or no on build number and on the hunt checklist.

Details

Hunt / verify

Slack paste: NetScaler: confirm fixed build (14.1-73.37 / 13.1-64.23 or FIPS match) today, then hunt httpd.php aliases, .ctxs.receiver, setuid /bin/sh, /tmp/.uxd*, WHIPSHOT/SLAPSHOT before closing the ticket.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.