☁️ Cloud & Compute Infrastructure

Attackers actively exploited CVE-2026-88772 in Citrix NetScaler appliances, bypassing authentication to gain root-level access; Citrix issued updates.

· ComputeLabs Research · from the September 29, 2026 edition

Mandiant Consulting and Google Threat Intelligence Group identified active exploitation of CVE-2026-88772 in Citrix NetScaler application delivery controller (ADC) and Gateway appliances in late September. The campaign had operated since at least early September, with evidence of likely impacts across government, financial services, technology, education, and legal and professional services organizations in North America and Europe.

The vulnerability bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE), establishing root-level access. Google states that it did not possess exploit code; its explanation of malformed handshake records causing memory corruption is based on frontline telemetry analysis.

The post-exploitation toolkit includes WHIPSHOT, a custom PHP web shell capable of concealing Base64-encoded command-and-control payloads in HTTP headers, and SLAPSHOT, a Python tunneling tool. In at least one observed intrusion, the attacker used the proxy for manual internal reconnaissance and credential theft.

Citrix issued guidance and updates, and Google urged defenders to prioritize patching while also providing containment and remediation guidance. Vendor disclosures additionally identified active exploitation of CVE-2026-88771, a separate vulnerability that should not be conflated with the detailed findings for CVE-2026-88772.

  • CVE-2026-88772
  • Citrix NetScaler
  • Citrix

All 19 stories from September 29, 2026