Citrix Vulnerability Exploited Since Early September: WHIPSHOT and SLAPSHOT Malware Families Used
A critical vulnerability in Citrix NetScaler ADC and Gateway has been exploited since early September, according to Google's Threat Intelligence Group. The flaw, CVE-2026-88772, was patched by Citrix, but it did not prevent victims from being affected.
The attackers are using the WHIPSHOT and SLAPSHOT malware families to gain access. Organizations in various sectors, including government, finance, tech, education, and legal services, have been impacted.
Citrix has also disclosed a second zero-day vulnerability, CVE-2026-88771, which is a critical RCE vulnerability that allows unauthenticated attackers to execute commands. The attacks appear to be largely uncoordinated and automated.
Google's security researchers recommend upgrading to NetScaler 14.1-73.37 or 13.1-64.23 (or later) and disabling DTLS if patching is not possible. They also suggest revoking sessions and rotating administrator passwords, SSH keys, and TLS certificates due to the high risk of credential leakage.