2026-09-28CRITICALexploitedCitrix confirms in-the-wild exploitation of two default-configuration NetScaler zero-days; CISA gives a three-day KEV deadline
SLAPSHOT
tool · tool:slapshot
Python TCP tunneler that Google GTIG and Mandiant saw on compromised NetScaler appliances, driven by the WHIPSHOT web shell over loopback and used to proxy traffic into victim networks for reconnaissance and credential theft (GTIG/Mandiant, 2026-09-29).
Coverage
1
first 2026-09-28 → last 2026-09-28
Latest activity
2026-09-30
Citrix confirms in-the-wild exploitation of two default-configuration NetScaler zero-days; CISA gives a…
Peak priority
critical
1 critical
Targets
public-sector
sectors: public-sector · regions: europe, switzerland
Sources cited
22
20 hosts
Action items (4)
Do-now tasks recorded on the entries about SLAPSHOT, newest first. Check the date before acting on an older one.
- Immediate action: Citrix confirms CVE-2026-88771 and CVE-2026-88772 are being exploited against unmitigated NetScaler ADC and NetScaler Gateway appliances right now, and Google's Mandiant reports exploitation since at least early September. CVE-2026-88771 requires no configuration at all: every default deployment is reachable by an unauthenticated attacker; CVE-2026-88772 is reachable wherever DTLS is enabled, which Citrix states is the default on any VPN virtual server. Citrix lists no workaround, and Mandiant's interim network controls (disable DTLS where it is not needed, block inbound UDP/443 upstream) cover CVE-2026-88772 only. Capture forensic evidence (logs, a configuration snapshot, a support bundle, a core dump) from each exposed appliance before patching, since the upgrade itself can destroy evidence of prior compromise, then upgrade to 14.1-73.37+ or 13.1-64.23+ (run2026-09-28CVE-2026-88771 +7
show ns variablefirst on 13.1; if it returns any variables, install 13.1-64.24 instead to avoid a known reboot loop) and run a compromise assessment on every appliance that was internet-facing. - Upgrade every internet-facing NetScaler ADC/Gateway to 14.1-73.37+ (14.1-FIPS 14.1-73.37 FIPS+) or 13.1-64.23+ (13.1-FIPS/NDcPP 13.1-37.279+) now; on a 13.1-branch appliance run2026-09-28CVE-2026-88771 +7
show ns variablefirst; if it returns any variables, install 13.1-64.24 instead to avoid a known reboot loop. Capture logs, a configuration snapshot, a support bundle and a core dump from each exposed appliance BEFORE patching, since the upgrade can remove forensic evidence of prior exploitation. - Run Mandiant's compromise checks on every NetScaler that was internet-facing and unpatched at any time since early September, patched or not; isolate any hit and halt HA configuration sync until both nodes are validated.2026-09-28CVE-2026-88771 +7
- Find any NetScaler ADC or Gateway still on the end-of-life 12.1 or 13.0 branches and decide isolation or replacement now: they receive no security updates and Citrix has not said whether they are affected.2026-09-28CVE-2026-88771 +7
Defender insights
What each entry about SLAPSHOT tells a defender to do, newest first.
Triage · detection
Story timeline
Hunting pivots
CVEs (exploited first)
Affected products
ATT&CK techniques (9 across 6 tactics)
9 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter: Unix Shell · Command and Scripting Interpreter: Python
- PersistenceServer Software Component: Web Shell
- Privilege EscalationAbuse Elevation Control Mechanism: Setuid and Setgid
- StealthMasquerading: Masquerade File Type · Indicator Removal
- Command and ControlApplication Layer Protocol: Web Protocols · Proxy: Internal Proxy
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗
Execution TA0002
T1059.004Command and Scripting Interpreter: Unix Shell×1
Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.
Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗
T1059.006Command and Scripting Interpreter: Python×1
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.
Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗
Privilege Escalation TA0004
T1548.001Abuse Elevation Control Mechanism: Setuid and Setgid×1
An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context. On Linux or macOS, when the setuid or setgid bits are set for an application binary, the application will run with the privileges of the owning user or group respectively. Normally an application is run in the current user’s context, regardless of which user or group owns the application. However, there are instances where programs need to be executed in an elevated context to function properly, but the user running them may not have the specific required privileges.
Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗
Stealth TA0005
T1036.008Masquerading: Masquerade File Type×1
Adversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file’s signature, extension, icon, and contents. Various file types have a typical standard format, including how they are encoded and organized. For example, a file’s signature (also known as header or magic bytes) is the beginning bytes of a file and is often used to identify the file’s type. For example, the header of a JPEG file, is <code> 0xFF 0xD8</code> and the file extension is either `.JPE`, `.JPEG` or `.JPG`.
Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗
T1070Indicator Removal×1
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.
Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗
Command and Control TA0011
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗
T1090.001Proxy: Internal Proxy×1
Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use internal proxies to manage command and control communications inside a compromised environment, to reduce the number of simultaneous outbound network connections, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between infected systems to avoid suspicion. Internal proxy connections may use common peer-to-peer (p2p) networking protocols, such as SMB, to better blend in with the environment.
Evidence: 2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev · ATT&CK page ↗
Entries about SLAPSHOT (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Citrix NetScaler×1
- Citrix NetScaler ADC/Gateway HTTP request smuggling, CTX697096, not reported exploited, CVSS4.0 9.3×1
- Citrix NetScaler ADC/Gateway HTTP URL-based expression policy bypass, CTX697096, not reported exploited, CVSS4.0 7.0×1
- Citrix NetScaler ADC/Gateway memory overflow to RCE/DoS via DTLS, exploited as a zero-day, CTX697096, CISA KEV 2026-09-27, CVSS4.0 9.5×1
- Citrix NetScaler ADC/Gateway memory overflow, Gateway/AAA virtual server, CTX697096, not reported exploited, CVSS4.0 8.8×1
- Citrix NetScaler ADC/Gateway memory overflow, non-HTTP L7 on LB/CS/CGNAT-LSN/NAT64, CTX697096, not reported exploited, CVSS4.0 8.8×1
- Citrix NetScaler ADC/Gateway memory overflow, Oracle-type LB virtual server, CTX697096, not reported exploited, CVSS4.0 8.8×1
- Citrix NetScaler ADC/Gateway predictable TCP ISN, CTX697096, not reported exploited, CVSS4.0 8.8×1
Where this entity is cited
Source distribution
- cert.europa.eu2 (9%)
- labs.watchtowr.com2 (9%)
- advisories.ncsc.nl1 (5%)
- ak-kurier.de1 (5%)
- bleepingcomputer.com1 (5%)
- censys.com1 (5%)
- cert.at1 (5%)
- cert.ssi.gouv.fr1 (5%)
- other12 (55%)
All cited sources (22)
- advisories.ncsc.nlNCSC-NLhttps://advisories.ncsc.nl/advisory?id=NCSC-2026-0394
- ak-kurier.deZIDKOR press release, as reprinted by AK-Kurierhttps://www.ak-kurier.de/akkurier/www/artikel/176375-kommunale-rechenzentren-schalten-fachverfahren-vorsorglich-ab
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
- censys.comCensyshttps://censys.com/advisory/cve-2026-10747-2/
- cert.atCERT.athttps://www.cert.at/de/warnungen/2026/9/kritische-sicherheitslucken-in-citrix-netscaler-adc-und-netscaler-gateway-aktiv-ausgenutzt-updates-verfugbar
- cert.europa.euCERT-EUhttps://cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771
- cert.europa.euCERT-EUhttps://cert.europa.eu/publications/security-advisories/2026-014/
- cert.ssi.gouv.frCERT-FR (ANSSI)https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1235/
- cisa.govCISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- cloud.google.comGoogle Threat Intelligence Group / Mandianthttps://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances
- esentire.comeSentire TRUhttps://www.esentire.com/security-advisories/update-ongoing-exploitation-of-citrix-netscaler-adc-and-netscaler-gateway-vulnerabilities-cve-2026-88771-cve-2026-88772
- greynoise.ioGreyNoisehttps://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation
- heise.deheise onlinehttps://www.heise.de/news/IT-Stoerung-trifft-Kommunalverwaltungen-in-Rheinland-Pfalz-11469044.html
- helpnetsecurity.comHelp Net Securityhttps://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/
- labs.watchtowr.comwatchTowr Labshttps://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/
- labs.watchtowr.comwatchTowr Labshttps://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/
- ncsc.gov.ukNCSC UKhttps://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
- rhein-zeitung.deRhein-Zeitung (dpa)https://www.rhein-zeitung.de/rheinland-pfalz/it-sicherheitsluecke-erste-staedte-melden-ende-der-stoerung_arid-4158892.html
- security-hub.ncsc.admin.chNCSC Switzerland CSHhttps://security-hub.ncsc.admin.ch/#/posts/13005
- support.citrix.comCitrix (Cloud Software Group)https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
- tenable.comTenablehttps://www.tenable.com/blog/frequently-asked-questions-about-reported-citrix-netscaler-zero-day-vulnerabilities
- watchtowr.comwatchTowrhttps://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/