Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances (opens in a new tab)
Why readMandiant confirms in-the-wild exploitation of NetScaler zero-day CVE-2026-88772 since early September and names the post-exploitation toolkit, including the WHIPSHOT PHP web shell.
Exploitation of CVE-2026-88772 bypasses authentication and forces an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to obtain root on NetScaler ADC and Gateway appliances. GTIG and Mandiant Consulting saw government, financial services, education and legal/professional services victims across North America and Europe, with activity dating to at least early September; a second zero-day, CVE-2026-88771, is also being exploited per Citrix. The actor toolkit includes custom PHP web shells such as WHIPSHOT that hide Base64 C2 payloads inside native HTTP headers, plus a Python companion component.