WHIPSHOT webshell found on 50,277 NetScaler appliances
Assessment
50,277 is Palo Alto Networks Unit 42's count of internet-exposed NetScaler instances that 'could potentially be vulnerable', from Cortex Xpanse telemetry as of 27 September 2026. It is an exposure figure, not a compromise count, and Unit 42 never said WHIPSHOT was found on them. WHIPSHOT is the name Mandiant and Google Threat Intelligence Group gave to one specific PHP tunnelling web shell; no source has published a count of appliances carrying it. Mandiant itself says it is aware of 'dozens' of impacted organisations.
Where this claim appeared
Decryption Digest · 2026-10-01
https://www.decryptiondigest.com/blog/netscaler-backdoor-persists-after-patching-whipshotWhat “False” means
Contradicted by primary sources. Reserved for claims checked directly against the authoritative record — an advisory that does not exist, a catalogue that does not list the entry, a directive that says something other than what is reported.
1 of 5 · rating scale
Assessed in
Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772: three weeks of exploitation before the patchThink this assessment is wrong? Report an error.