critical Cve 2026 88771 · Exploits

Citrix NetScaler Zero-Days Planted Webshells Weeks Before the Patch

Data graphic: NetScaler zero-days, patch then hunt. Both flaws score CVSS 4.0 9.5 and are stamped exploited CISA KEV, 27 Sep ; 50,277 exposed instances; CISA KEV deadline 30 Sep.
AK

Threat intelligence editor · Updated Oct 2, 2026, 8:05 AM EDT

Two pre-auth NetScaler ADC and Gateway flaws, CVE-2026-88771 and CVE-2026-88772, were exploited for weeks before the fix. Patch, then hunt for webshells.

Two unauthenticated flaws in Citrix NetScaler ADC and NetScaler Gateway were exploited as zero-days for weeks before Citrix published a fix on 27 September 2026. One is a command injection that works on a default configuration. The other is a memory overflow in the appliance's DTLS handling. Attackers used both to plant PHP webshells and a tunneling daemon on the box. Installing the fixed build does not remove any of that, so every internet-facing NetScaler that ran an affected build in September needs a compromise check as well as an upgrade.

CVE-2026-88771 is an improper input validation flaw (CWE-20) that lets an unauthenticated attacker execute arbitrary commands. CVE-2026-88772 is a memory overflow that leads to remote code execution or denial of service, and it needs DTLS to be enabled, which it is by default on VPN virtual servers. Citrix rates both 9.5 Critical under CVSS 4.0. NVD scores CVE-2026-88771 at 9.8 and CVE-2026-88772 at 8.1 under CVSS 3.1, the lower score reflecting high attack complexity.

CISA added both to its Known Exploited Vulnerabilities catalog on 27 September, the day of disclosure, with a remediation deadline of 30 September for federal civilian agencies. Both KEV entries are flagged for forensic triage under BOD 26-04, so agencies are expected to look for signs of compromise, not only to patch.


Who is affected

The flaws affect NetScaler ADC and NetScaler Gateway on the two supported branches, including the FIPS and NDcPP builds:

Product lineVulnerableFixed in
NetScaler ADC and Gateway 14.1before 14.1-73.3714.1-73.37 and later
NetScaler ADC and Gateway 13.1before 13.1-64.2313.1-64.23 and later
NetScaler ADC 14.1-FIPSbefore 14.1-73.37 FIPS14.1-73.37 FIPS and later
NetScaler ADC 13.1-FIPS and 13.1-NDcPPbefore 13.1-37.27913.1-37.279 and later

Versions 12.1 and 13.0 are end of life and receive no fix. Appliances still on those branches have to move to a supported build.

The exposure is large. Palo Alto Networks' Cortex Xpanse counted 50,277 exposed instances that could be vulnerable as of 27 September. Mandiant and the Google Threat Intelligence Group (GTIG) say organizations in North America and Europe were likely impacted, across government, financial services, technology, education, and legal and professional services. Rapid7 had identified two organizations compromised through CVE-2026-88771 at the time of its write-up.

The same bulletin, CTX697096, fixes six more NetScaler flaws, CVE-2026-88773 through CVE-2026-88778. None is reported as exploited. The most severe is CVE-2026-88773, an HTTP request smuggling flaw rated 9.3. Four are rated 8.8: memory overflows in Gateway or AAA (CVE-2026-88775), Oracle load-balancer (CVE-2026-88776) and LB/CS or CGNAT-LSN/NAT64 (CVE-2026-88777) configurations, and predictable TCP initial sequence numbers (CVE-2026-88778). CVE-2026-88774, a policy bypass involving URL expressions, is rated 7.0.

Data graphic: CVSS 4.0 scores for the eight flaws in Citrix bulletin CTX697096. CVE-2026-88771 and CVE-2026-88772 score 9.5 and were exploited; CVE-2026-88773 9.3; 88775 to 88778 8.8; 88774 7.0.

The eight flaws fixed in CTX697096 by CVSS 4.0 score. Only the two highlighted were exploited before the fix.


Weeks of exploitation before the patch

The exploitation started well before disclosure. Unit 42's reconstruction begins with fingerprinting from two hosts on 21 August. Between 4 and 24 September, an actor repeatedly pulled files from the appliance's /vpn/scripts/linux/ folder, where the DTLS-delivered webshells were staged. Rapid7 saw the earliest command-injection attempts at 2026-09-20T14:28:43 UTC, and on 21 September Unit 42 watched an actor drop a PHP webshell in a three-stage process. Mandiant puts the start of exploitation at "at least early September."

Private warnings ran ahead of the advisory. BleepingComputer reported that IT suppliers told some customers to shut their NetScalers down before any details were public, and that the Dutch NCSC sent pre-notifications to organizations in the Netherlands. Citrix's bulletin followed on 27 September, confirming that "exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed."

This is the fourth NetScaler flaw CISA has added to KEV in 2026, after CVE-2026-3055 in March, CVE-2026-8452 on 26 August and CVE-2026-19490 on 9 September.

Data graphic: timeline of NetScaler attacks. Fingerprinting 21 Aug, webshell requests from 4 Sep Unit 42 , command injection 20 Sep Rapid7 , Citrix fix and CISA KEV listing 27 Sep, KEV due 30 Sep.

Attack activity against NetScaler began more than five weeks before Citrix published fixed builds. Sources: Unit 42, Rapid7, Citrix, CISA.


How the two flaws work

CVE-2026-88771: a log line that becomes a command

watchTowr traced the command injection to ns_monuploadd_err.pl, a Perl script that scans the appliance's logs for a Pitboss message saying the packet engine (NSPPE) died. The script cuts fields out of the last matching line with grep, tail, sed and awk, then interpolates them into a backtick shell command:

find /var/core -name ${WR_PPE_COREFILE_NAME}* -print | tail -1

Nothing checks that the parsed fields look like a core file name. An attacker can write a forged Pitboss line into the log by sending it as the login parameter of an unauthenticated POST to /nf/auth/doAuthentication.do, for example:

pitboss PPE unexpectedly died NSPPE;`id>/var/tmp/watchTowr`;# X

When the script next runs, which watchTowr says is typically within 24 hours, the semicolons split the command and the payload executes as root. The attacker sends one request and waits. No authentication is needed and the default configuration is affected.

CVE-2026-88772: a DTLS reassembly overflow

The second flaw sits in nsppe, NetScaler's core packet engine. According to watchTowr, the DTLS reassembly function copies a chain of NetScaler buffers into a fixed 35,840-byte scratch buffer without checking the total size. The parser trusts the declared message length to find headers but uses the real fragment lengths when it rebuilds the message. watchTowr's proof of concept completes the DTLS cookie handshake, then sends 120 crafted records of about 1,450 bytes each and spills 137,825 bytes past the buffer. From there it hijacks an object's method pointer and uses a ROP chain to call mprotect and run shellcode. The fixed build tracks how much room is left before each copy.

Mandiant describes the same path in the wild: malformed, fragmented DTLS record headers during the handshake corrupt memory in NSPPE and give the attacker code execution with root privileges. A failed attempt crashes the packet engine, and that crash leaves log entries defenders can look for.


What the attackers left behind

Mandiant and GTIG named two tools:

  • WHIPSHOT, a PHP webshell that hides Base64-encoded command-and-control traffic inside ordinary HTTP headers and answers with HTTP 404 responses while it tunnels TCP.
  • SLAPSHOT, a Python tunneler that binds a port on 127.0.0.1 and proxies traffic into the internal network for reconnaissance and credential theft. It writes its port to /tmp/.uxdport and holds a lock on /tmp/.uxdlock.

The shells are disguised as Gateway client downloads. The attackers changed the Apache configuration so the web server runs .deb or .sig files as PHP, and staged the shells under /netscaler/gui/vpn/scripts/linux/. One variant aliased /vpn/media/*.ico requests to .sig files. To keep root, they set the SUID bit on /bin/sh. Unit 42 recovered RC4-encrypted PHP shells named nsgclient18.deb, nsgser18.deb and nsg64.deb, and a separate shell, .ctxs.receiver, in /var/netscaler/logon/LogonPoint/custom/.

None of this is removed by an upgrade, and the configuration change keeps working after it. An appliance patched on the KEV deadline can still be running a shell it picked up earlier in September.


What defenders should do

1. Patch now. Move to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS or 13.1-37.279 FIPS/NDcPP. Replace 12.1 and 13.0 appliances.

2. If you cannot patch today, cut the DTLS path. Mandiant advises disabling DTLS on internet-facing Gateway virtual servers that do not need it, and blocking inbound UDP/443 upstream. This does nothing for CVE-2026-88771, which needs no optional feature.

3. Hunt on every appliance that was exposed in September, patched or not. Mandiant's checks include:

# Apache directives that turn non-PHP files into PHP
grep -En -i "application/x-httpd-php|php_flag|AliasMatch" /etc/httpd.conf

# PHP code hiding in the Gateway client-download and portal folders
grep -rlE "<\?php|eval\(|base64_decode\(|shell_exec\(" /var/netscaler/gui/ \
  /netscaler/ns_gui/ /var/vpn/ /netscaler/portal/ 2>/dev/null

# SLAPSHOT artifacts and a SUID root shell (alert on -rwsr-xr-x)
ls -la /tmp/.uxdport* /tmp/.uxdlock
ls -l /bin/sh

In the logs, look for DTLSv1.0 handshake failures with the reason "Handshake failure-Internal Error", followed by pitboss reporting that it is "NOT restarting NSPPE". For CVE-2026-88771, look for forged Pitboss text in authentication logs that came in through the login field. Citrix's IOC scanner and its guidance for suspected compromise (CTX694799) cover the vendor's own checks.

4. If you find anything, treat the appliance as owned. Mandiant recommends revoking active sessions and rotating every secret the box holds: admin credentials, SSH keys, TLS certificates, LDAP bind accounts, RADIUS shared secrets and TACACS credentials. SLAPSHOT exists to reach the internal network, so assume credentials that passed through the Gateway were exposed.

5. Block and search for the published infrastructure. Defanged indicators from Mandiant and Unit 42:

143.198.7[.]94        scanning / staging (Mandiant)
157.254.167[.]12      exploitation / installation (Mandiant)
104.248.244[.]66      fingerprinting from 21 Aug (Unit 42)
77.83.199[.]39        fingerprinting, webshell drop (Unit 42)
78.47.24[.]217        webshell drop, 21 Sep (Unit 42)
139.180.152[.]138     webshell drop, 21 Sep (Unit 42)
193.149.176[.]207     attacker infrastructure (Unit 42)
HTTP headers          NSC_LDAP, NSC_CLIENTTYPE, X-UX / X-UX-<n>
URI paths             /vpn/scripts/linux/nsginstaller*.deb, /vpn/scripts/linux/nsgclient*.deb, /vpn/media/*.ico
Files                 /tmp/.uxdport, /tmp/.uxdlock, nsgclient18.deb, nsgser18.deb, nsg64.deb, .ctxs.receiver

NetScaler sits at the edge and holds the credentials of everyone who logs in through it, which makes it an obvious target. These two flaws were exploited for weeks with no advisory, so patching closes the hole but says nothing about whether someone already got in. Check for compromise as well.


Sources

Keep reading

All latest →
  1. highExploitsWordPress Core Flaw CVE-2026-87902 Drew Exploit Attempts on Patch Day7 min
  2. criticalExploitsCheck Point Management Servers Were a Zero-Day for Two Months Before the Fix6 min
  3. criticalExploitsCisco SD-WAN Manager Zero-Day CVE-2026-76504: One Encoded Character Unlocks the Admin API5 min
  4. criticalExploitsExploited FortiMail Flaw Has No Patch Yet: Disable IBE Now5 min
  5. criticalExploitsUnder Active Attack: Cisco ISE Zero-Day (CVE-2026-76460) Grants Remote Unauthenticated Admin Access8 min
  6. criticalExploitsShieldCrash Zero-Day Analysis: Bypassing Microsoft Defender's ShieldBreak Fix (CVE-2026-69414) for Arbitrary SYSTEM File Reads7 min