CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

WHIPSHOT

malware · malware:whipshot

PHP web shell that Google GTIG and Mandiant recovered from NetScaler appliances compromised in the CVE-2026-88772 campaign; it hides Base64 commands in HTTP request headers, answers with a spoofed 404 and relays over loopback to the SLAPSHOT tunneler (GTIG/Mandiant, 2026-09-29).

Coverage
1
first 2026-09-28 → last 2026-09-28
Latest activity
2026-09-30
Citrix confirms in-the-wild exploitation of two default-configuration NetScaler zero-days; CISA gives a…
Peak priority
critical
1 critical
Targets
public-sector
sectors: public-sector · regions: europe, switzerland
Sources cited
22
20 hosts

Action items (4)

Do-now tasks recorded on the entries about WHIPSHOT, newest first. Check the date before acting on an older one.

  • Immediate action: Citrix confirms CVE-2026-88771 and CVE-2026-88772 are being exploited against unmitigated NetScaler ADC and NetScaler Gateway appliances right now, and Google's Mandiant reports exploitation since at least early September. CVE-2026-88771 requires no configuration at all: every default deployment is reachable by an unauthenticated attacker; CVE-2026-88772 is reachable wherever DTLS is enabled, which Citrix states is the default on any VPN virtual server. Citrix lists no workaround, and Mandiant's interim network controls (disable DTLS where it is not needed, block inbound UDP/443 upstream) cover CVE-2026-88772 only. Capture forensic evidence (logs, a configuration snapshot, a support bundle, a core dump) from each exposed appliance before patching, since the upgrade itself can destroy evidence of prior compromise, then upgrade to 14.1-73.37+ or 13.1-64.23+ (run show ns variable first on 13.1; if it returns any variables, install 13.1-64.24 instead to avoid a known reboot loop) and run a compromise assessment on every appliance that was internet-facing.
    2026-09-28CVE-2026-88771 +7
  • Upgrade every internet-facing NetScaler ADC/Gateway to 14.1-73.37+ (14.1-FIPS 14.1-73.37 FIPS+) or 13.1-64.23+ (13.1-FIPS/NDcPP 13.1-37.279+) now; on a 13.1-branch appliance run show ns variable first; if it returns any variables, install 13.1-64.24 instead to avoid a known reboot loop. Capture logs, a configuration snapshot, a support bundle and a core dump from each exposed appliance BEFORE patching, since the upgrade can remove forensic evidence of prior exploitation.
    2026-09-28CVE-2026-88771 +7
  • Run Mandiant's compromise checks on every NetScaler that was internet-facing and unpatched at any time since early September, patched or not; isolate any hit and halt HA configuration sync until both nodes are validated.
    2026-09-28CVE-2026-88771 +7
  • Find any NetScaler ADC or Gateway still on the end-of-life 12.1 or 13.0 branches and decide isolation or replacement now: they receive no security updates and Citrix has not said whether they are affected.
    2026-09-28CVE-2026-88771 +7

Defender insights

What each entry about WHIPSHOT tells a defender to do, newest first.

2026-09-28CRITICALexploitedCitrix confirms in-the-wild exploitation of two default-configuration NetScaler zero-days; CISA gives a three-day KEV deadline

Triage · detection

Story timeline

  1. 2026-09-28CVE-2026-88771 / CVE-2026-88772, Citrix NetScaler ADC and Gateway: unauthenticated pre-auth RCE zero-days exploited before a patch existed (CVSS 4.0 9.5)
    deep-diveCitrix confirms in-the-wild exploitation of two default-configuration NetScaler zero-days; CISA gives a three-day KEV deadline
ATT&CK techniques (9 across 6 tactics)

9 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application
  • ExecutionCommand and Scripting Interpreter: Unix Shell · Command and Scripting Interpreter: Python
  • PersistenceServer Software Component: Web Shell
  • Privilege EscalationAbuse Elevation Control Mechanism: Setuid and Setgid
  • StealthMasquerading: Masquerade File Type · Indicator Removal
  • Command and ControlApplication Layer Protocol: Web Protocols · Proxy: Internal Proxy

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗

Execution TA0002

T1059.004Command and Scripting Interpreter: Unix Shell×1

Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.

Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗

T1059.006Command and Scripting Interpreter: Python×1

Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.

Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗

Persistence TA0003

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗

Privilege Escalation TA0004

T1548.001Abuse Elevation Control Mechanism: Setuid and Setgid×1

An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context. On Linux or macOS, when the setuid or setgid bits are set for an application binary, the application will run with the privileges of the owning user or group respectively. Normally an application is run in the current user’s context, regardless of which user or group owns the application. However, there are instances where programs need to be executed in an elevated context to function properly, but the user running them may not have the specific required privileges.

Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗

Stealth TA0005

T1036.008Masquerading: Masquerade File Type×1

Adversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file’s signature, extension, icon, and contents. Various file types have a typical standard format, including how they are encoded and organized. For example, a file’s signature (also known as header or magic bytes) is the beginning bytes of a file and is often used to identify the file’s type. For example, the header of a JPEG file, is <code> 0xFF 0xD8</code> and the file extension is either `.JPE`, `.JPEG` or `.JPG`.

Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗

T1070Indicator Removal×1

Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.

Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗

T1090.001Proxy: Internal Proxy×1

Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use internal proxies to manage command and control communications inside a compromised environment, to reduce the number of simultaneous outbound network connections, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between infected systems to avoid suspicion. Internal proxy connections may use common peer-to-peer (p2p) networking protocols, such as SMB, to better blend in with the environment.

Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗

Entries about WHIPSHOT (1)

2026-09-28 · view entry permalink →

CRITICALCVE-2026-88771 +7exploitedupdatedNATOA1

CVE-2026-88771 / CVE-2026-88772, Citrix NetScaler ADC and Gateway: unauthenticated pre-auth RCE zero-days exploited before a patch existed (CVSS 4.0 9.5)

Citrix's security bulletin CTX697096, published 2026-09-27, fixes eight NetScaler ADC / NetScaler Gateway vulnerabilities, two of which were already being exploited as zero-days before any fix existed (Citrix, 2026-09-27). CVE-2026-88771 (CWE-20, improper input validation, CVSS 4.0 9.5) lets an unauthenticated remote attacker execute arbitrary commands on every NetScaler ADC/Gateway deployment in its default configuration; no feature needs to be enabled first. CVE-2026-88772 (CWE-119, memory overflow to RCE or DoS, CVSS 4.0 9.5) is reachable wherever DTLS is enabled, which Citrix states is the default on any VPN virtual server, so most VPN-fronting Gateway deployments meet the precondition unless DTLS was explicitly disabled. Citrix's own bulletin states plainly: "Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed" (Citrix, 2026-09-27). CISA added both to its Known Exploited Vulnerabilities catalog on 2026-09-27 with a 2026-09-30 remediation due date, requiring compliance with BOD 26-04 forensic-triage guidance (CISA Known Exploited Vulnerabilities Catalog, 2026-09-27), and CERT-EU's advisory the same day states "Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild" and recommends a compromise assessment on every internet-facing appliance (CERT-EU, 2026-09-27).

The disclosure path itself is a defender-relevant data point. NetScaler administrators reported being told by IT suppliers and security teams to shut appliances down over the weekend of 26-27 September, before any CVE identifier or vendor advisory existed, tracing to a pre-notification NCSC-NL reportedly sent to its constituency; NCSC-NL declined to confirm the leaked notice's contents to BleepingComputer (BleepingComputer, 2026-09-27) but published its own public advisory NCSC-2026-0394 the same day once Citrix's bulletin shipped (NCSC-NL, 2026-09-27). watchTowr independently and publicly flagged credible rumors of unpatched, in-the-wild NetScaler RCEs on 2026-09-26, a day ahead of Citrix's own bulletin. No public attribution of the exploiting activity exists; watchTowr's FAQ states "No attribution has been made public," while noting NetScaler perimeter appliances have historically been targeted by both state-sponsored and ransomware-affiliated actors, consistent with the CitrixBleed (CVE-2023-4966) and CitrixBleed 2 (CVE-2025-5777) history on the same product line (watchTowr, 2026-09-27).

The same bulletin fixes six configuration-dependent companion flaws not reported exploited: an HTTP request-smuggling flaw (CVE-2026-88773, CVSS 9.3), a policy-bypass flaw via HTTP URL-based expressions (CVE-2026-88774, CVSS 7.0), three further memory-overflow conditions gated respectively on a Gateway/AAA virtual server, an Oracle-type load-balancing virtual server, or a non-HTTP Layer-7 protocol on an LB/CS/CGNAT-LSN/NAT64 device (CVE-2026-88775/88776/88777, each CVSS 8.8), and a predictable-TCP-ISN weakness (CVE-2026-88778, CVSS 8.8) whose remediation is not covered by the version upgrade alone: it additionally requires enabling Enhanced ISN Generation. This is a distinct CVE family from CVE-2026-19490 and from the CitrixBleed/CitrixBleed 2 lineage named above; watchTowr states directly that appliances already patched for CVE-2026-19490 remain vulnerable to CVE-2026-88771/88772 unless running one of the new fixed builds (watchTowr, 2026-09-27). Fixed builds are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1-37.279 (FIPS/NDcPP); watchTowr flags an upgrade caveat on the 13.1 branch: run show ns variable first, and if it returns any variables, install 13.1-64.24 instead to avoid a known reboot loop during the upgrade.

Detection and hunting. Citrix has published no workaround for either exploited flaw (watchTowr, 2026-09-27); Mandiant's interim network controls for CVE-2026-88772 alone are described in the update below, so the priority is upgrading, not mitigating in place. Before patching, capture logs, a configuration snapshot, a support bundle and a core dump from every appliance that has been internet-facing, since the upgrade can overwrite forensic evidence of prior compromise; CISA's guidance under BOD 26-04 recommends the same sequence (CISA Known Exploited Vulnerabilities Catalog, 2026-09-27). A limited IOC scan is available from 14.1-73.36+ with telemetry enabled via the NetScaler Console Security Advisory page or through Citrix Support, but Citrix itself cautions the indicators do not cover every exploitation technique (watchTowr, 2026-09-27), so a clean scan is not proof an appliance was not already compromised before patching; a compromise assessment (authentication logs for anomalous sessions, unexpected configuration changes, unfamiliar scheduled tasks or processes on the management plane) is the only way to build that confidence.

Triage: the discriminator for CVE-2026-88771 is that no legitimate administrative or user path reaches the vulnerable input-validation code path without a valid session: any successful, unauthenticated command execution on the appliance is the signal, not a benign lookalike to rule out. For CVE-2026-88772, DTLS handling anomalies (crashes, unexpected restarts, or malformed-record errors in VPN vServer logs) on an appliance where DTLS was not deliberately disabled are the discriminator worth hunting for, since legitimate DTLS traffic does not trigger the memory-overflow condition.

Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.

A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands

Citrix (Cloud Software Group) 2026-09-27

Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild.

CERT-EU 2026-09-27

No attribution has been made public.

watchTowr 2026-09-27

The Command Injection happens in the next line, when Perl interpolates that string into another backtick command

It is worth mentioning that this is not limited to a single endpoint. Any endpoint or port that logs data controlled in an HTTP header can trigger this vulnerability.

watchTowr Labs 2026-09-28

organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, which has been ongoing since at least early September

The DTLS and UDP/443 controls below are specific to CVE-2026-88772 and should not be relied on to mitigate CVE-2026-88771.

Google Threat Intelligence Group / Mandiant 2026-09-29

observed a threat actor exploiting CVE-2026-88771 against Internet-facing Citrix NetScaler Gateway appliances as early as September 5th, more than three weeks before the vulnerability was publicly disclosed

eSentire TRU 2026-09-29

The vulnerable function then copies that entire chain into the 35,840-byte scratch buffer without checking whether it fits.

watchTowr Labs 2026-09-28

NetScaler ADC and NetScaler Gateway versions 12.1 and 13.0 have reached end-of-life (EOL) and no longer receive security updates, and Citrix has not said whether they are affected by these vulnerabilities.

Tenable 2026-09-27

Patching does not remove persistence an attacker already installed.

Censys 2026-09-29

fueled by the publication of a root-cause analysis and a proof-of-concept exploit for CVE-2026-88771, which is remotely exploitable on unpatched devices with the default configuration

Help Net Security 2026-09-29

It is not a successful cyberattack, but a precaution to protect the data until the vulnerability is closed (translated from German)

Rhein-Zeitung (dpa) 2026-09-29

The IT teams probably brought the Citrix NetScaler software up to date. (translated from German)

heise online 2026-09-29
Updaterun 2026-09-29T0405Z-inteltechniquessourcesevidenceactionsbody

watchTowr Labs' root-cause analysis, published 2026-09-28, names the actual vulnerable component behind CVE-2026-88771: not the nsppe packet engine that has carried most historical NetScaler CVEs, but ns_monuploadd_err.pl, a Perl script that periodically scans NetScaler system logs for Pitboss "PPE unexpectedly died" crash messages to recover a core-dump filename (watchTowr Labs, 2026-09-28). The pre-patch script extracted that filename with an unsanitized shell pipeline and re-interpolated the attacker-influenced string into a second backtick command: "The Command Injection happens in the next line, when Perl interpolates that string into another backtick command" (watchTowr Labs, 2026-09-28), executing as root because nearly every NetScaler process runs with root privileges. Critically, the trigger is not confined to the SSLVPN/AAA login form watchTowr used to demonstrate it: "it is worth mentioning that this is not limited to a single endpoint. Any endpoint or port that logs data controlled in an HTTP header can trigger this vulnerability" (watchTowr Labs, 2026-09-28): failed logins, rate-limited requests and arbitrary request parameters or User-Agent headers can all poison the log the monitor script later parses. Citrix's fix replaces the unsafe pipeline with a strict regex capture that only accepts a well-formed PPE name and numeric PID and executes find via Perl's list form rather than shell interpolation. watchTowr also clarifies exploitation-status granularity across the eight-CVE bulletin: only CVE-2026-88771 and CVE-2026-88772 are confirmed exploited, matching this entry's existing table, and has published a public detection-artefact tool. NCSC Switzerland's Cyber Security Hub, NCSC UK and CERT-FR (CERTFR-2026-AVI-1235) each published same-day advisories on 2026-09-28 independently confirming active exploitation.

Updaterun 2026-09-30T0404Z-intelsummaryimmediate_actiontagscvesentitiestechniquessourcesevidenceactionsbody

Exploitation predates the bulletin. Google's Mandiant and Threat Intelligence Group identified in-the-wild exploitation of CVE-2026-88772 and report that the campaign has run since at least early September, with organizations in North America and Europe in government, financial services, technology, education, and legal and professional services likely impacted (GTIG/Mandiant, 2026-09-29). eSentire independently reports CVE-2026-88771 exploited against internet-facing NetScaler Gateway appliances as early as 5 September (eSentire, 2026-09-29), and GreyNoise recorded a failed pre-disclosure attempt on 24 September that already used the setuid-and-handler playbook described below (GreyNoise, 2026-09-28). GTIG and GreyNoise name no actor. CERT-EU traced the activity through NetScaler logs from the European Court of Auditors and the European Central Bank, which showed requests carrying Base64-encoded shell commands in the HTTP User-Agent header (CERT-EU, 2026-09-28). An appliance upgraded after the 27 September bulletin may therefore already have been compromised: "Patching does not remove persistence an attacker already installed" (Censys, 2026-09-29).

What the actor leaves behind. After the DTLS exploit runs shellcode as root, a first-stage web shell rewrites the appliance web-server configuration so that files with non-script extensions run as PHP; in one variant an alias maps requests for image files under the VPN media path onto a staged shell, so the traffic looks like image fetches, and the shells answer with HTTP 404 while taking Base64 commands from HTTP request headers, including NSC-prefixed ones (GTIG/Mandiant, 2026-09-29). The installer sets the setuid bit on /bin/sh so later web requests run as root, scrubs its staging path from /etc/crontab and reboots the appliance to apply the change (GTIG/Mandiant, 2026-09-29). The PHP shell WHIPSHOT relays requests over loopback to SLAPSHOT, a Python TCP tunneler that Mandiant saw used for internal reconnaissance and credential theft in at least one intrusion (GTIG/Mandiant, 2026-09-29).

Exploit availability for CVE-2026-88772. GTIG states it holds no exploit code (GTIG/Mandiant, 2026-09-29). watchTowr published a root-cause analysis and a detection-artifact generator on 29 September: DTLS handshake reassembly keeps almost the whole record for each one-byte fragment, so after 120 records the buffer chain holds about 174 KB, which a packet-engine function copies into a 35,840-byte scratch buffer without a size check (watchTowr Labs, 2026-09-29). NCSC Switzerland's advisory now lists a proof of concept for both CVEs (NCSC-CH, 2026-09-29), and Help Net Security reports the activity turned into opportunistic mass exploitation after a public root-cause analysis and proof of concept for CVE-2026-88771, while its text says there was no public proof of concept for CVE-2026-88772 (Help Net Security, 2026-09-29).

Interim controls and containment. For appliances that cannot be patched at once Mandiant lists three network restrictions: disabling DTLS on internet-facing Gateway virtual servers where it is not needed and blocking inbound UDP/443 at an upstream firewall or edge router (local ACLs let the traffic reach the packet engine first) are specific to CVE-2026-88772 and "should not be relied on to mitigate CVE-2026-88771", while upstream IP allow-listing, where source ranges are predictable, is not scoped to one CVE and may be impractical for large remote workforces (GTIG/Mandiant, 2026-09-29). For a suspected compromise it advises isolating the node, halting high-availability configuration sync until both nodes are validated because a compromised node can replicate a modified web-server configuration to the standby, restricting appliance egress, and, after patching, rotating appliance and integration credentials and terminating Gateway and ICA sessions (GTIG/Mandiant, 2026-09-29). NetScaler 12.1 and 13.0 are end of life and no longer receive security updates, and Citrix has not said whether they are affected (Tenable, 2026-09-27). Censys counts 42,735 exposed NetScaler ADC and Gateway hosts, with Switzerland among the countries at roughly 4% each; these are exposed instances, not confirmed-vulnerable ones (Censys, 2026-09-29).

Hunting. By telemetry class: appliance web-server configuration containing handler or alias directives that point public paths at script directories; script content in the client plug-in and media directories, which should hold compiled clients and static assets; 404 responses with multi-kilobyte bodies or long processing times on media paths; the setuid bit on /bin/sh; lock and port-pointer files in the temp directory; and, for CVE-2026-88772, a DTLS handshake-failure "Internal Error" line in the syslog together with a packet-engine termination line and a watchdog "NOT restarting" line in the FreeBSD system log, which NetScaler does not forward to a SIEM by default (GTIG/Mandiant, 2026-09-29). Triage: GTIG lists the handshake-failure line and the packet-engine termination with its watchdog line as the two log artifacts of successful exploitation, so look for them together and pair them with a check for configuration drift.

A shared municipal operator shut down as a precaution. The two municipal data centres of the Rhineland-Palatinate association ZIDKOR shut down centrally hosted specialist applications on Sunday 27 September after a security vulnerability became known, taking resident-registration, ID-card, vehicle-registration and civil-registry services offline across all 194 full-time administered municipalities, cities and counties while they installed the vendor's patches; the operators say no successful cyberattack occurred, and each administration ran its own continuity plan with no central instruction (ZIDKOR release via AK-Kurier, 2026-09-28). Mainz and Kaiserslautern reported regular service again on the morning of 29 September (dpa via Rhein-Zeitung, 2026-09-29). The operators name no vendor; heise assesses that the trigger was probably the NetScaler updates released that weekend, a link it added to its article after publication (heise online, 2026-09-29). Cantonal and communal IT providers that host citizen services behind a shared NetScaler front end face the same trade-off between shutting down to patch and staying reachable.

Builds on: The precondition is wider than the headline version numbers suggest; on older builds a Gateway… · CVE-2026-8451, Citrix NetScaler ADC/Gateway: pre-auth SAML memory overread (CitrixBleed…

vulnerability28 Sep 04:04Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Deep dive1

Source distribution

  • cert.europa.eu2 (9%)
  • labs.watchtowr.com2 (9%)
  • advisories.ncsc.nl1 (5%)
  • ak-kurier.de1 (5%)
  • bleepingcomputer.com1 (5%)
  • censys.com1 (5%)
  • cert.at1 (5%)
  • cert.ssi.gouv.fr1 (5%)
  • other12 (55%)
All cited sources (22)