Citrix NetScaler Flaw Now Confirmed Deployed for Root Access and Web Shells in Real Attacks (CVE-2026-88772)
Scope: Citrix NetScaler ADC and NetScaler Gateway with DTLS Enabled (On by Default on VPN Virtual Servers)
Severity: Red
Mandiant Consulting and Google's Threat Intelligence Group confirmed on September 30, 2026 that unknown threat actors have been actively exploiting CVE-2026-88772, one of two NetScaler zero-days Citrix disclosed just two days ago, to compromise organizations across North America and Europe in the government, financial services, technology, education, and legal and professional services sectors. The flaw is a memory overflow in how NetScaler's Datagram Transport Layer Security handling works, and exploiting it bypasses authentication entirely by crashing a core NetScaler process, which the device then restarts in a way that hands the attacker root-level access from the very first request. Once inside, attackers have deployed a previously unreported PHP web shell named WHIPSHOT, built to hide Base64-encoded command-and-control instructions inside ordinary HTTP headers so they blend into normal traffic and evade casual log review. Because NetScaler appliances sit at the network edge and are frequently excluded from endpoint detection tooling, they remain an especially attractive target for exactly this kind of attack. Organizations that have not applied Citrix's fix released two days ago must do so immediately, and should not assume patching alone resolves the risk, since root access may have already been established before the update was applied. Review devices for unfamiliar PHP files and unusual outbound HTTP traffic patterns as indicators of prior compromise.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.