decrypted · 30 september 2026 · vulnerabilities and patching · uk policy and law

Citrix has patched NetScaler, but a patch will not remove the web shell

The NetScaler story we covered on Sunday has moved. Citrix has now published patches for its two zero-days, the NCSC has issued an alert, and Mandiant and Google Threat Intelligence Group have described what attackers left behind on compromised appliances. The advice is no longer just "patch". It is "patch, then check whether someone was already inside".

What has changed

Citrix's bulletin covers eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two are exploited: CVE-2026-88771, which lets an unauthenticated attacker run commands, and CVE-2026-88772, a memory overflow that can give code execution or a crash when DTLS is enabled. The NCSC alert, dated 28 September, says affected builds are 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23. Mandiant says attacks on organisations in North America and Europe began in early September, well before any patch existed. Counts of exposed appliances differ: Censys reported 42,735 vulnerable hosts, while Palo Alto Networks put it above 50,000.

How the break-in works

Think of a post room clerk who must open every parcel at the door, before checking who sent it. Mandiant assesses that malformed DTLS record headers, a way of encrypting traffic over UDP, corrupt memory inside the appliance's packet engine. The attacker's parcel is folded so the spillage lands as instructions, which then run as root on the underlying FreeBSD system. No password is involved at any point.

Once inside, the attackers install a web shell called WHIPSHOT. It is disguised as a Debian package file, takes commands hidden in HTTP headers, and always answers with a 404, so a casual glance at the logs shows nothing. They also edit the web server configuration so that .deb files are handled as PHP. A second tool, SLAPSHOT, is a small Python proxy that opens a port and forwards traffic into the internal network, which is where credential theft begins.

What a defender sees

Very little. Published indicators include PHP handlers for .deb files in httpd.conf, the setuid bit set on /bin/sh, .deb or .sig files that contain PHP, and a file named /tmp/.uxdport. Patching does not remove a web shell that is already there. That is why the NCSC says, if possible, to isolate the affected system and replace it with a new, fully up-to-date one, noting this may cause an outage. That is a rebuild, not a patch window. Disabling DTLS and blocking inbound UDP/443 closes the CVE-2026-88772 route, but it does not protect against CVE-2026-88771.

The Secure by Design lesson

An internet-facing gateway that parses hostile input before authentication, and runs as root when it does, turns one memory bug into total control. CyberScoop reports that Citrix has appeared on CISA's exploited list five times in 2026 and 26 times since late 2021, and that the company stayed publicly silent for more than 36 hours after exploitation rumours began. Coalition's Joe Toomey called that silence "unconscionably irresponsible".

You cannot redesign the vendor's code, but you can design around it. Know which edge devices you run and who receives their advisories. Keep a known-good configuration so a rebuild takes hours, not days. Put logging somewhere the appliance cannot rewrite. Ask suppliers, at renewal, whether their pre-authentication code is isolated and unprivileged.

Also this week

The ICO is now the Information Commission. Under the Data (Use and Access) Act 2025, the regulator moves today from a single Commissioner to a board, and the seven non-executive members appointed in July take up their roles. The ICO says it will keep the ICO name and its existing functions. Law firm Lewis Silkin's reading of the Act points to sharper investigatory tools, including compelling witnesses to attend interviews and requesting reports from approved persons, which the ICO says it will use where necessary in the most serious cases. My opinion: a board can change tone, and after a breach the regulator will want to hear from named people. Update policies and processor contracts that cite the Information Commissioner, and decide now who would sit in that interview.

OpenSSL fixes a DTLS bug that leaks memory. Disclosed on 29 September, CVE-2026-84782 is rated High. When a handshake message is resent while a larger one is partly sent, the wrong buffer position is used, so heap memory can travel to the other side as unencrypted handshake data, or the process can crash. Laurent Gaffie of Secorizon reported it on 17 August. Fixed releases are 4.0.3, 3.6.5, 3.5.9 and 3.4.8, while the 3.0, 1.1.1 and 1.0.2 branches are fixed only for premium support customers. It is a separate bug from the NetScaler ones and shares only DTLS with them, but check the OpenSSL versions bundled inside your products, especially anything doing WebRTC or call encryption. Free support for old branches is a design choice with a bill attached.

Sources

If you want a second pair of eyes on your edge devices or your incident plan, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.