NetScaler Zero-Days CVE-2026-88771 and CVE-2026-88772 Exploited to Deploy Web Shells

· Original article ↗

Summary

Unit 42 details in-the-wild exploitation of two critical NetScaler vulnerabilities, including attack chains that deploy web shells for command execution and persistence. Its telemetry found 50,277 potentially exposed instances as of Sept. 27, 2026.

Key points

  • Both unauthenticated vulnerabilities affect NetScaler ADC and Gateway systems and have CVSS v4.0 scores of 9.5; one enables remote code execution, while the other can cause remote code execution or denial of service.
  • Attackers exploited CVE-2026-88772 through crafted DTLS traffic and placed PHP web shells in the appliance’s client-package directory.
  • A separate CVE-2026-88771 attack chain poisoned logs, triggering a vulnerable Perl script to execute commands and install a web shell.
  • The analyzed shells could execute commands, upload files, and exfiltrate data; one used modified Apache configuration to maintain access through a web-accessible path.
  • Unit 42 observed exploitation from August into September, followed by widespread scanning and testing after public disclosure on Sept. 27.
  • Palo Alto Networks telemetry identified 50,277 potentially vulnerable exposed instances as of Sept. 27, 2026.
  • Citrix updates should be applied promptly, but patching alone may not remove attacker persistence; defenders should check exposure, preserve evidence, and investigate suspicious sessions, outbound connections, and logging gaps.

Article Details

Attack Vectors
  • Before public disclosure, hosts requested NetScaler UI files in activity consistent with version fingerprinting.
  • The reported CVE-2026-88772 chain sent crafted DTLS traffic to vulnerable NetScaler devices and was associated with .deb web shells hosted in the appliances' /vpn/scripts/linux/ directory.
  • The observed CVE-2026-88771 chain placed a Base64-encoded dropper command in a User-Agent log entry, inserted command text into a failed-login log entry, and relied on a vulnerable Perl script to execute that text and deploy a PHP web shell.
  • One analyzed PHP web shell accepted operator commands through HTTP headers, cookies, and request parameters; it supported command execution, file exfiltration, and file upload.
  • Another PHP web shell used a hidden .ctxs.receiver file, a hard-coded cookie value, and a command-bearing cookie. The attacker patched Apache configuration to execute it through CSS-looking URL aliases.
Defensive Notes
  • Update Citrix software to the latest versions and check appliances against the preconditions in the Citrix security advisory. Patching does not remove access already established by an attacker.
  • Isolate vulnerable systems and preserve a NetScaler VPX snapshot, remote syslog and NetScaler Console logs, a technical support bundle, and a packet engine core dump.
  • Hunt for suspicious administrative sessions, unexpected outbound connections, and unexplained logging gaps. Unit 42 states that these are general hunting suggestions, not behaviors specifically observed in this activity.
  • Unit 42 provides a query for CVE-2026-88771 log poisoning; a query match does not establish successful exploitation on a patched device.
  • Palo Alto Networks says Advanced Threat Prevention signature 97562 is designed to block exploitation of CVE-2026-88771, Advanced URL Filtering identifies known associated IP addresses, and Cortex XDR and XSIAM detect post-exploit activity.

Indicators of compromise

TypeIndicatorContext
IPV4104[.]248[.]244[.]66Host observed requesting NetScaler files in activity consistent with version fingerprinting; also listed as a network indicator.
IPV4104[.]248[.]74[.]206Source of requests for .deb web-shell files during the reported DTLS exploitation activity.
IPV4104[.]28[.]215[.]136Cloudflare WARP address used to request .deb web-shell files and subsequently observed in anomalous authentication-page requests.
IPV4104[.]28[.]215[.]137Cloudflare WARP address used to request .deb web-shell files and subsequently observed in anomalous authentication-page requests; also listed as a network indicator.
IPV4104[.]28[.]247[.]136Cloudflare WARP address used to request .deb web-shell files and subsequently observed in anomalous authentication-page requests; also listed as a network indicator.
IPV4104[.]28[.]247[.]137Additional IP address observed sending anomalous requests to the appliance's authentication page during the web-shell activity.
IPV4137[.]184[.]91[.]207Source of requests for .deb web-shell files during the reported DTLS exploitation activity.
IPV4139[.]180[.]152[.]138Source involved in the observed three-stage PHP web-shell deployment.
IPV4142[.]93[.]85[.]227Source of requests for .deb web-shell files during the reported DTLS exploitation activity.
IPV4162[.]33[.]178[.]9Source of requests for .deb web-shell files during the reported activity; also listed as a network indicator.
IPV4167[.]99[.]111[.]203Source of requests for .deb web-shell files during the reported DTLS exploitation activity.
IPV4193[.]149[.]176[.]207Source of repeated .deb web-shell file requests and anomalous authentication-page requests; also listed as a network indicator.
IPV4216[.]245[.]184[.]164IP address explicitly listed under network indicators of compromise.
IPV445[.]61[.]136[.]143IP address explicitly listed under network indicators of compromise.
IPV466[.]135[.]19[.]18Source of requests for .deb web-shell files during the reported DTLS exploitation activity.
IPV466[.]227[.]183[.]84IP address explicitly listed under network indicators of compromise.
IPV477[.]83[.]199[.]39Host involved in NetScaler fingerprinting and the observed three-stage web-shell deployment; also listed as a network indicator.
IPV478[.]47[.]24[.]217Host involved in NetScaler fingerprinting and the observed three-stage web-shell deployment.
SHA2561bd314b661396c7086f6367fbbb48025e03ca2de69c073d53a8b0a38aa5fbb7dHash of a text file representing the Base64 payload used to drop and execute a PHP web shell.
SHA25679c65fa04541032e251fa4796b97800374b63c7982593dd1a2e0db605d429186Hash of a text file representing the decoded web-shell deployment script.
SHA256ae22ef2517b5c0fb47f78745b9cb5260acee0e751b89bcd354640ff8bc8d29ecHash of the analyzed nsg64.deb PHP web-shell file.

MITRE ATT&CK

CVE

Vendors

Products

Countries

Related Articles