NetScaler Zero-Days CVE-2026-88771 and CVE-2026-88772 Exploited to Deploy Web Shells

Summary
Unit 42 details in-the-wild exploitation of two critical NetScaler vulnerabilities, including attack chains that deploy web shells for command execution and persistence. Its telemetry found 50,277 potentially exposed instances as of Sept. 27, 2026.
Key points
- Both unauthenticated vulnerabilities affect NetScaler ADC and Gateway systems and have CVSS v4.0 scores of 9.5; one enables remote code execution, while the other can cause remote code execution or denial of service.
- Attackers exploited CVE-2026-88772 through crafted DTLS traffic and placed PHP web shells in the appliance’s client-package directory.
- A separate CVE-2026-88771 attack chain poisoned logs, triggering a vulnerable Perl script to execute commands and install a web shell.
- The analyzed shells could execute commands, upload files, and exfiltrate data; one used modified Apache configuration to maintain access through a web-accessible path.
- Unit 42 observed exploitation from August into September, followed by widespread scanning and testing after public disclosure on Sept. 27.
- Palo Alto Networks telemetry identified 50,277 potentially vulnerable exposed instances as of Sept. 27, 2026.
- Citrix updates should be applied promptly, but patching alone may not remove attacker persistence; defenders should check exposure, preserve evidence, and investigate suspicious sessions, outbound connections, and logging gaps.
Article Details
- Attack Vectors
- Before public disclosure, hosts requested NetScaler UI files in activity consistent with version fingerprinting.
- The reported CVE-2026-88772 chain sent crafted DTLS traffic to vulnerable NetScaler devices and was associated with .deb web shells hosted in the appliances' /vpn/scripts/linux/ directory.
- The observed CVE-2026-88771 chain placed a Base64-encoded dropper command in a User-Agent log entry, inserted command text into a failed-login log entry, and relied on a vulnerable Perl script to execute that text and deploy a PHP web shell.
- One analyzed PHP web shell accepted operator commands through HTTP headers, cookies, and request parameters; it supported command execution, file exfiltration, and file upload.
- Another PHP web shell used a hidden .ctxs.receiver file, a hard-coded cookie value, and a command-bearing cookie. The attacker patched Apache configuration to execute it through CSS-looking URL aliases.
- Defensive Notes
- Update Citrix software to the latest versions and check appliances against the preconditions in the Citrix security advisory. Patching does not remove access already established by an attacker.
- Isolate vulnerable systems and preserve a NetScaler VPX snapshot, remote syslog and NetScaler Console logs, a technical support bundle, and a packet engine core dump.
- Hunt for suspicious administrative sessions, unexpected outbound connections, and unexplained logging gaps. Unit 42 states that these are general hunting suggestions, not behaviors specifically observed in this activity.
- Unit 42 provides a query for CVE-2026-88771 log poisoning; a query match does not establish successful exploitation on a patched device.
- Palo Alto Networks says Advanced Threat Prevention signature 97562 is designed to block exploitation of CVE-2026-88771, Advanced URL Filtering identifies known associated IP addresses, and Cortex XDR and XSIAM detect post-exploit activity.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 104[.]248[.]244[.]66 | Host observed requesting NetScaler files in activity consistent with version fingerprinting; also listed as a network indicator. |
| IPV4 | 104[.]248[.]74[.]206 | Source of requests for .deb web-shell files during the reported DTLS exploitation activity. |
| IPV4 | 104[.]28[.]215[.]136 | Cloudflare WARP address used to request .deb web-shell files and subsequently observed in anomalous authentication-page requests. |
| IPV4 | 104[.]28[.]215[.]137 | Cloudflare WARP address used to request .deb web-shell files and subsequently observed in anomalous authentication-page requests; also listed as a network indicator. |
| IPV4 | 104[.]28[.]247[.]136 | Cloudflare WARP address used to request .deb web-shell files and subsequently observed in anomalous authentication-page requests; also listed as a network indicator. |
| IPV4 | 104[.]28[.]247[.]137 | Additional IP address observed sending anomalous requests to the appliance's authentication page during the web-shell activity. |
| IPV4 | 137[.]184[.]91[.]207 | Source of requests for .deb web-shell files during the reported DTLS exploitation activity. |
| IPV4 | 139[.]180[.]152[.]138 | Source involved in the observed three-stage PHP web-shell deployment. |
| IPV4 | 142[.]93[.]85[.]227 | Source of requests for .deb web-shell files during the reported DTLS exploitation activity. |
| IPV4 | 162[.]33[.]178[.]9 | Source of requests for .deb web-shell files during the reported activity; also listed as a network indicator. |
| IPV4 | 167[.]99[.]111[.]203 | Source of requests for .deb web-shell files during the reported DTLS exploitation activity. |
| IPV4 | 193[.]149[.]176[.]207 | Source of repeated .deb web-shell file requests and anomalous authentication-page requests; also listed as a network indicator. |
| IPV4 | 216[.]245[.]184[.]164 | IP address explicitly listed under network indicators of compromise. |
| IPV4 | 45[.]61[.]136[.]143 | IP address explicitly listed under network indicators of compromise. |
| IPV4 | 66[.]135[.]19[.]18 | Source of requests for .deb web-shell files during the reported DTLS exploitation activity. |
| IPV4 | 66[.]227[.]183[.]84 | IP address explicitly listed under network indicators of compromise. |
| IPV4 | 77[.]83[.]199[.]39 | Host involved in NetScaler fingerprinting and the observed three-stage web-shell deployment; also listed as a network indicator. |
| IPV4 | 78[.]47[.]24[.]217 | Host involved in NetScaler fingerprinting and the observed three-stage web-shell deployment. |
| SHA256 | 1bd314b661396c7086f6367fbbb48025e03ca2de69c073d53a8b0a38aa5fbb7d | Hash of a text file representing the Base64 payload used to drop and execute a PHP web shell. |
| SHA256 | 79c65fa04541032e251fa4796b97800374b63c7982593dd1a2e0db605d429186 | Hash of a text file representing the decoded web-shell deployment script. |
| SHA256 | ae22ef2517b5c0fb47f78745b9cb5260acee0e751b89bcd354640ff8bc8d29ec | Hash of the analyzed nsg64.deb PHP web-shell file. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe attacker staged a Base64-encoded dropper command in a User-Agent log entry and decoded it during exploitation.T1036 · MasqueradingApache aliases exposed a hidden PHP web shell through CSS-looking paths, disguising command traffic as ordinary asset requests.T1059.004 · Unix ShellThe exploit chain decoded a staged command and piped it to sh; the analyzed web shell also executed shell commands.T1071.001 · Web ProtocolsThe analyzed web shells received operator commands through HTTP request headers, cookies, or parameters and returned command output in HTTP responses.T1190 · Exploit Public-Facing ApplicationAttackers exploited vulnerabilities in exposed NetScaler devices to establish initial access and deploy web shells.T1505.003 · Web ShellAttackers deployed PHP web shells on NetScaler appliances to execute commands and maintain access.T1548.001 · Setuid and SetgidThe web-shell deployment command set SUID and SGID bits on /bin/sh so subsequent commands could run with root privileges.T1573.001 · Symmetric CryptographyThe analyzed nsg64.deb web shell used RC4 with a hard-coded key to encrypt command-and-control communication.
CVE
Vendors
CitrixIn a Citrix report that details several CVEs, they noted that CVE-2026-88771 and CVE-2026-88772 have been exploited in the wild.Palo Alto Networks27, 2026, Palo Alto Networks Cortex Xpanse has identified 50,277 exposed instances that could potentially be vulnerable to these CVEs based on our telemetry.
Products
Advanced Threat PreventionNext-Generation Firewall with Advanced Threat PreventionAdvanced URL FilteringAdvanced URL FilteringCortex XDRCortex XDR and XSIAMCortex Xpanse27, 2026, Palo Alto Networks Cortex Xpanse has identified 50,277 exposed instances that could potentially be vulnerable to these CVEs based on our telemetry.NetScaler ADC(RCE) or denial of service (DoS) on the Datagram Transport Layer Security (DTLS) configuration on NetScaler ADC and NetScaler Gateway systemsNetScaler ConsoleLogs on remote syslog servers and NetScaler ConsoleNetScaler Gatewayunauthenticated actor to run commands against NetScaler Application Delivery Controller (ADC) and NetScaler Gateway systemsNetScaler VPXA NetScaler VPX instance snapshotXSIAMCortex XDR and XSIAM