Mandiant published its analysis on 30 September 2026 of attacks against Citrix NetScaler ADC and Gateway appliances that were running before any patch existed. Three days earlier, on 27 September, CISA had issued an alert about the same appliances. It lists eight identifiers, from CVE-2026-88771 to CVE-2026-88778, and singles out the first two as critical zero-days that can each lead to remote code execution on their own.

Getting in is one request. What the operators did afterwards is the part worth reading, because it was built to outlive the fix.

Root through a handshake that never finishes

The route Mandiant describes runs through the DTLS handshake on UDP port 443. Malformed or fragmented record headers corrupt heap memory, bypass authentication and bring down the NetScaler Packet Processing Engine, the process that handles traffic on the appliance. What the attacker is left holding is root-level access on a device that sits at the edge of the network, in front of everything it protects.

There is nothing for a user to click and nothing for a mail filter to catch. The appliance is reachable because that is its job.

A web shell addressed as a missing icon

With root, the operators edited the appliance's own web server configuration, and two changes did most of the work.

The first registered file extensions that nobody reads as code — .deb and .sig — to be executed as PHP.

The second added an alias so that a request for a file under the interface's media path ending in .ico, the kind of request a browser makes for an icon, is answered by a .sig file sitting in a scripts directory.

The result is a web shell you reach by asking for an icon that does not exist. The request looks like ordinary interface noise. The response is an HTTP 404, the one status code no dashboard alerts on, carrying kilobytes of payload in a body nobody reads.

WHIPSHOT, SLAPSHOT, and a tunnel that tidies up

Mandiant names two tools on top of that access.

WHIPSHOT is a PHP web shell that hides its base64-encoded instructions inside ordinary HTTP headers, so the command traffic does not appear in a URL or in a request body where an inspection rule would look for it.

SLAPSHOT is a Python proxy that tunnels TCP connections from the appliance into the internal network, with a fifteen-minute idle timeout and its own cleanup. It is not left sitting there between sessions, which is also why a scan at the wrong moment finds nothing.

Through that tunnel: reconnaissance inside the network the appliance fronts, and credentials carried back out the same way.

Why the patch is the second step, not the first

The persistence does not depend on the vulnerability. Mandiant describes the set-user-ID bit being added to the system shell, so that running it grants root without any exploit at all. The web server is restarted to load the new configuration, the appliance is rebooted, and installation paths are stripped out of the scheduled-tasks file so the work does not show up where an administrator would look first.

A patched appliance with a set-user-ID shell and two extra lines in its web server configuration is still the attacker's appliance. The update closes the door; it does not evict anyone.

That is the reason CISA's alert tells organisations to check for indications of compromise before applying updates, and the reason Mandiant's own remediation list starts with rotating credentials and revoking sessions rather than with the upgrade. It is the same order of operations the federal directive set out for the Cisco firewall manager earlier this month: evidence first, patch second, because patching a compromised box destroys the memory that would have proved it.

Who was hit

Mandiant places the affected organisations in North America and Europe, in government, financial services, technology, education, and legal and professional services. It gives no number of victims and no attribution to any group.

Citrix's fixed builds are 14.1-73.37 and later on the 14.1 track, and 13.1-64.23 and later on the 13.1 track, with separate builds for FIPS and NDcPP deployments.

What to do

  • Upgrade to the fixed build for your track, and treat the FIPS and NDcPP appliances as their own task rather than assuming they are covered.
  • Collect evidence before you upgrade if the appliance was internet-reachable. Memory before the reboot, and a copy of the web server configuration before it is replaced.
  • Rotate everything the appliance holds: local administrator accounts, LDAP, RADIUS and TACACS credentials, and the TLS certificates. Then revoke administrative, Gateway, VPN and session-level logins.
  • Hunt specifically. Check the web server configuration for handlers that map .deb or .sig to PHP and for alias rules pointing media paths at scripts. Check whether the system shell carries the set-user-ID bit. Look for the temporary lock files Mandiant lists, and for DTLS handshake failures that line up with the packet engine restarting.
  • If you cannot patch today, disable DTLS where the service allows it and block inbound UDP 443 at the perimeter.

What is not established

  • How many organisations were compromised. Neither Mandiant nor CISA gives a count.
  • Who is behind it. Mandiant publishes no attribution.
  • When exploitation began, and how long it ran before the appliances were patched.
  • Whether the other six identifiers in CISA's alert were used in these intrusions, or simply fixed alongside them.
  • The CVSS scores. CISA's alert does not carry them.