Google Cloud BlogMandiant22 min readadvanced
Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
Summary
Mandiant and Google identified active exploitation of two zero‑day bugs in Citrix NetScaler ADC/Gateway that let attackers gain root via malformed DTLS packets, then persist with custom PHP web shells and a Python tunneler. The blog details the exploit mechanics, persistence tricks, detection signatures, and remediation steps.
- CVE‑2026‑88772 triggers a heap overflow in the NetScaler packet engine during DTLS handshake, granting root on the underlying FreeBSD system.
- Attackers modify /etc/httpd.conf to treat .deb and .sig files as PHP, deploying lightweight web shells (WHIPSHOT) that execute Base64 payloads from HTTP headers.
- The Python tool SLAPSHOT creates a local TCP tunnel with a custom binary/JSON protocol, enabling internal reconnaissance and credential theft.
- Detect compromise via SSL_HANDSHAKE_FAILURE logs, NSPPE process termination messages, and unexpected MIME handler entries in httpd.conf.
Security engineers protecting edge devices need to know these zero‑day exploits and how to detect and remediate them before attackers gain persistent root access.
6/10





