State-backed hackers used NetScaler zero-day for weeks
Mandiant says suspected state hackers exploited CVE-2026-88772 from early September, planting WHIPSHOT and SLAPSHOT web shells.
By Sam Reyes · Published · Updated · 4 min read

Attackers exploited a Citrix NetScaler zero-day for at least three weeks before anyone noticed, CyberScoop reports.
The timeline
- September 3: earliest known exploitation of CVE-2026-88772, Mandiant says.
- September 24: GreyNoise sees an exploit attempt, BleepingComputer reports.
- September 25–26: IT providers and the Dutch NCSC privately urge organizations to switch off NetScaler devices.
- September 27: Citrix discloses and patches the flaws.
Who was hit
Mandiant CTO Charles Carmakal says dozens of organizations in North America and Europe were affected, across government, finance, education, telecoms, legal and professional services. He attributes the attacks to "advanced and suspected state-sponsored threat actors".
How the attacks worked
According to SecurityWeek, attackers gained root access, changed the web server configuration and planted previously unseen malware, including a PHP web shell called WHIPSHOT and a tunnelling tool.
What defenders should do
- Treat any NetScaler that was internet-facing and unpatched in September as potentially compromised.
- Check for compromise and preserve evidence before patching.
- Rotate credentials that passed through the appliance.

