Attackers exploiting a pair of Citrix NetScaler zero-day vulnerabilities installed two previously undocumented malware families, dubbed WHIPSHOT and SLAPSHOT, to maintain root-level access and move laterally inside victim networks spanning government, financial services, education, legal, and professional-services organizations across North America and Europe.
Two Zero-Days Dubbed “PitScaler” Affect NetScaler ADC and Gateway
Researchers have named the vulnerability pair “PitScaler.” CVE-2026-88771 is an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments, giving attackers a direct path into the appliance without needing valid credentials. CVE-2026-88772 is a memory-overflow flaw that requires DTLS to be enabled on the target system, a narrower precondition than the first flaw’s unauthenticated, universal exposure.
GreyNoise detected active scanning and exploitation tied to the two CVEs on September 24. Citrix’s public disclosure of the malware and attacker tactics followed five days later, on September 29. The gap between detection and public disclosure is attributed to private warnings that were sent to affected organizations ahead of the public announcement, giving some victims early notice before the broader security community learned the details.
The exposure created by CVE-2026-88771 is particularly significant because it requires no authentication at all and applies to every NetScaler ADC and Gateway deployment, rather than to a subset running a specific optional feature. CVE-2026-88772’s narrower requirement, that DTLS be enabled, limits its exposure to organizations that have turned on that specific transport-layer feature, making the unauthenticated RCE flaw the more universally applicable entry point for attackers scanning for vulnerable appliances.
WHIPSHOT Acts as a Web Shell While SLAPSHOT Tunnels Traffic
Once inside a vulnerable NetScaler appliance, attackers installed custom PHP web shells disguised as legitimate files in the NetScaler LogonPoint directory. Alongside these disguised shells, researchers identified two distinct, previously undocumented malware families. WHIPSHOT is a PHP web shell that functions as an HTTP proxy, letting attackers route traffic through the compromised appliance. SLAPSHOT is a Python-based TCP tunneling tool used specifically for lateral movement, allowing attackers to reach deeper into a victim’s network from the initial NetScaler foothold.
Attackers Used Non-Executable File Extensions to Hide PHP Code
The intrusion set relied on several novel evasion tactics documented in the disclosure. Attackers executed PHP code through files carrying non-executable extensions such as .deb, .sig, and .ico, a technique designed to avoid detection tools that flag standard executable or script file types. To further mask their activity, the malware returned fake HTTP 404 “not found” responses when probed, making compromised endpoints appear inactive to defenders scanning for signs of the web shells.
Modified /bin/sh Permissions Established Persistent Root Access
Beyond the web shells and tunneling tool, attackers modified permissions on /bin/sh, the standard command shell binary on the affected systems, to establish persistent root-level access that would survive routine remediation efforts targeting the initially planted files. This permission change gave attackers a durable foothold independent of the WHIPSHOT and SLAPSHOT files themselves, meaning removing the visible malware alone would not necessarily restore the system to a secure state.
Federal Remediation Ordered After KEV Listing
CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog on September 28, one day before the malware disclosure, and has ordered federal agencies to remediate the flaws. Citrix has released patches for both CVEs. Organizations running affected NetScaler ADC or Gateway deployments are being urged to hunt for WHIPSHOT and SLAPSHOT indicators and inspect their LogonPoint directories for unauthorized files, since patching alone would not remove malware or backdoored permissions already planted before the fix was applied.
The confirmed victim sectors, spanning government, financial services, education, legal, and professional-services organizations on two continents, combined with evidence of root-level persistence and internal network tunneling, mark a material escalation from an initial vulnerability listing into a campaign with demonstrated post-exploitation capability. Organizations that patched only after the September 28 KEV listing, without also checking for the described indicators, may still host active WHIPSHOT or SLAPSHOT infections planted during the exploitation window that began in early September.
