Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Mandiant and GTIG report exploitation of Citrix NetScaler appliances in September 2026

Key Takeaways
- Unknown threat actors exploited a patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances in September 2026.
- Activity was observed by Mandiant Consulting and Google GTIG targeting government, financial services, technology, education, and legal/professional services sectors in North America and Europe.
- Actors gained root access and deployed WHIPSHOT and SLAPSHOT malware on affected appliances.
Related Security News
CISA Advises of Sensitive Information Exposure in Johnson Controls EasyIO Neo Series Controllers
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Industrial Control Systems advisory regarding CVE-2026-64892, a vulnerability in Johnson Controls EasyIO Neo Series EC and CW Controllers that could allow an attacker to gain access to sensitive information. The flaw stems from improper access controls in building automation controllers and impacts four specific firmware versions. Johnson Controls has released fixed firmware versions V3.3b64 (EC) and V3.3b26 (CW) to address the issue.