ThreatPaper
False

WHIPSHOT webshell found on 50,277 NetScaler appliances

Assessment

50,277 is Palo Alto Networks Unit 42's count of internet-exposed NetScaler instances that 'could potentially be vulnerable', from Cortex Xpanse telemetry as of 27 September 2026. It is an exposure figure, not a compromise count, and Unit 42 never said WHIPSHOT was found on them. WHIPSHOT is the name Mandiant and Google Threat Intelligence Group gave to one specific PHP tunnelling web shell; no source has published a count of appliances carrying it. Mandiant itself says it is aware of 'dozens' of impacted organisations.

Where this claim appeared

Decryption Digest · 2026-10-01

https://www.decryptiondigest.com/blog/netscaler-backdoor-persists-after-patching-whipshot

What “False” means

Contradicted by primary sources. Reserved for claims checked directly against the authoritative record — an advisory that does not exist, a catalogue that does not list the entry, a directive that says something other than what is reported.

1 of 5 · rating scale

Assessed in

Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772: three weeks of exploitation before the patch

Think this assessment is wrong? Report an error.