CISA’s federal remediation date for the two exploited NetScaler remote code execution flaws is Wednesday, Sep 30, 2026. Mandiant’s new write-up, covered by BleepingComputer on Sep 29, shows what operators who only “scheduled the patch” are missing: custom web shells, httpd.conf tricks that make images and CSS execute as PHP, and a Python tunnel Mandiant calls SLAPSHOT.
If the appliance is still on a vulnerable build, patch first. If it was Internet-facing before Saturday’s fix, hunt before you declare the ticket closed.
A patched NetScaler with setuid
/bin/shand a fake 404 web shell is not a closed ticket. The 5-Minute Cyber BriefDon’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
What happened
Citrix disclosed CVE-2026-88771 and CVE-2026-88772 on Sep 27 (bulletin CTX697096) after national CERTs and suppliers privately warned customers over the weekend. Both flaws enable unauthenticated remote code execution. CISA added them to KEV the same day with a Sep 30 due date. Monday’s brief covered the patch itself; today’s story is the post-exploitation picture Mandiant published afterward.
Mandiant says exploitation of CVE-2026-88772 bypasses authentication, crashes the NetScaler Packet Processing Engine, and yields root on the FreeBSD appliance. Attackers installed PHP web shells and rewrote /etc/httpd.conf so non-executable extensions (.deb, .sig, .ico under /vpn/media/, CSS-looking paths) executed as PHP. Some shells returned fake HTTP 404 responses while running commands.
Two previously undocumented malware families appear in the report. WHIPSHOT is a PHP web shell disguised as a Debian package in the VPN scripts directory. It proxies to SLAPSHOT, a Python TCP tunnel that bridges the appliance to internal hosts for credential theft and recon. Attackers also set the setuid bit on /bin/sh so web shell commands kept root. GreyNoise earlier observed similar staging, including a password-protected shell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver. Mandiant links observed malware to CVE-2026-88772; Citrix says CVE-2026-88771 has been exploited too. Disabling DTLS only helps against 88772.
Why it matters
Edge ADCs and Gateways are still the shortest path into a lot of networks, and they rarely run the same EDR stack as a laptop. Federal agencies hit the BOD clock today; everyone else should treat that date as the outer bound, not a suggestion.
The Mandiant detail changes the definition of done. Installing 14.1-73.37 or 13.1-64.23 closes the bug. It does not remove WHIPSHOT, SLAPSHOT, setuid shells, or httpd aliases already planted.
What to do first
- Patch now to Citrix’s fixed builds (14.1-73.37, 13.1-64.23, and matching FIPS/NDcPP trains per CTX697096). There is no complete workaround for both bugs.
- Preserve evidence before reboot/upgrade when compromise is plausible: support bundle, disk snapshot, memory capture if you can.
- Hunt Mandiant/GreyNoise indicators listed below before you close the change ticket.
- Do not rely on DTLS-off alone. That mitigation does not cover CVE-2026-88771.
- Rotate credentials that traversed the Gateway (LDAP bind, RADIUS secrets, SSO certs, admin accounts) if IoCs appear.
Forward this
If your team runs Citrix NetScaler ADC or Gateway: today’s federal due date is the reminder to finish the upgrade, then ask whether anyone hunted for Mandiant’s WHIPSHOT/SLAPSHOT web shells and a setuid /bin/sh. A patched box can still be an attacker’s tunnel. Ask for a yes or no on build number and on the hunt checklist.
Details
- CVE-2026-88771: improper input validation RCE, default NetScaler ADC/Gateway deployments; exploited
- CVE-2026-88772: memory overflow RCE/DoS when DTLS enabled (on by default on VPN vServer); exploited
- Fixed builds: 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, 13.1-37.279 FIPS/NDcPP (see CTX697096)
- KEV due: Sep 30, 2026 (added Sep 27, 2026)
- Malware: WHIPSHOT (PHP web shell / proxy), SLAPSHOT (Python TCP tunnel); setuid /bin/sh persistence
- Sectors observed: government, financial services, education, legal, professional services in North America and Europe (Mandiant)
Hunt / verify
- Inspect
/etc/httpd.conffor unexpected Alias/AliasMatch or PHP handlers on.deb,.sig,.ico, CSS paths, or/vpn/media/. - Look for
.ctxs.receiver, suspicious.deb/.sigfiles containing PHP, and PHP in VPN script directories. - Check whether
/bin/shhas the setuid bit; review unexpected NSPPE crashes and reboots. - Hunt
/tmp/.uxdport,/tmp/.uxdlock, and Python processes launched withnohupor Base64 payloads (SLAPSHOT). - Review connections involving GreyNoise-observed 149.104.78.141 around Sep 24 and Mandiant’s published IoCs.
Slack paste: NetScaler: confirm fixed build (14.1-73.37 / 13.1-64.23 or FIPS match) today, then hunt httpd.php aliases, .ctxs.receiver, setuid /bin/sh, /tmp/.uxd*, WHIPSHOT/SLAPSHOT before closing the ticket.
Sources
- BleepingComputer: Hackers exploit Citrix NetScaler zero-day to deploy web shells (Sep 29, 2026)
- BleepingComputer: CISA orders feds to patch exploited Citrix flaws by Wednesday (Sep 28, 2026)
- Citrix CTX697096 security bulletin
- CISA: Adds two Known Exploited Vulnerabilities (Sep 27, 2026)
- CISA alert: Critical zero-days in Citrix NetScaler ADC/Gateway
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.