proomt

Search

Search posts, papers, and topics

All posts

Google Cloud BlogMandiant22 min readadvanced

Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances

Summary

Mandiant and Google identified active exploitation of two zero‑day bugs in Citrix NetScaler ADC/Gateway that let attackers gain root via malformed DTLS packets, then persist with custom PHP web shells and a Python tunneler. The blog details the exploit mechanics, persistence tricks, detection signatures, and remediation steps.

  • CVE‑2026‑88772 triggers a heap overflow in the NetScaler packet engine during DTLS handshake, granting root on the underlying FreeBSD system.
  • Attackers modify /etc/httpd.conf to treat .deb and .sig files as PHP, deploying lightweight web shells (WHIPSHOT) that execute Base64 payloads from HTTP headers.
  • The Python tool SLAPSHOT creates a local TCP tunnel with a custom binary/JSON protocol, enabling internal reconnaissance and credential theft.
  • Detect compromise via SSL_HANDSHAKE_FAILURE logs, NSPPE process termination messages, and unexpected MIME handler entries in httpd.conf.

Security engineers protecting edge devices need to know these zero‑day exploits and how to detect and remediate them before attackers gain persistent root access.

6/10

Related reading

  1. September 16, 2026 security incident: how we responded to a LiteSpeed zero-day attack

    Hostinger detected a zero‑day exploit in LiteSpeed Web Server on a Brazil server on Sep 16 2026, giving the attacker root access and compromising 399 accounts. The team isolated the server, coordinated with LiteSpeed to patch the vulnerability, rolled out the fix fleet‑wide, and restored affected sites from backups within the same day.

    Hostingerhostinger.com2 minpostmortem