Mastodon Mastodon Mastodon Mastodon

Exploitation of CVE-2026-88771/88772 in Citrix NetScaler: attack techniques and defense steps

Photo of author

CyberSecureFox Editorial Team

Published:

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway — CVE-2026-88772 and CVE-2026-88771 (both with CVSS 9.5) — are already being actively exploited to bypass authentication and obtain root access on edge devices, followed by the deployment of stealthy web shells and tunnels into corporate networks; organizations in the public sector, and in financial, technology, education and legal industries in North America and Europe have already fallen victim, so all Citrix NetScaler owners must immediately apply patches, check for signs of compromise, and if updating is not possible, consider temporarily disabling or isolating the devices.

Technical details of the vulnerabilities and attack chains

CVE-2026-88772: DTLS memory overflow and a path to a root shell without authentication

CVE-2026-88772 is a memory overflow in DTLS protocol handling in the NetScaler Packet Processing Engine (NSPPE) component. The vulnerability affects Citrix NetScaler ADC and NetScaler Gateway used as application delivery controllers and VPN gateways. The 9.5 score reflects that this is a pre-authentication vector: an attacker can remotely achieve code execution without having credentials.

The key defect is tied to how NSPPE handles fragmented DTLS handshake messages. As shown in the analysis by watchTowr Labs, NetScaler:

  • trusts the fragment_length field in the DTLS header, treating it as the actual fragment size;
  • at the same time, relies on the length field as the size of the entire message (for example, 120 bytes);
  • reassembles the handshake message from multiple fragments without checking whether the data fits into the shared buffer.

In practice this means an attacker can send, for example, 120 fragments, each with length=120 but fragment_length=1 and sequential offsets 0–119. From the reassembly logic’s point of view this is a 120-byte message, but each real packet (about 1459 bytes) is stored in NetScaler Buffers (NSB) and stitched into a shared scratch buffer of 35,840 bytes. Since the vulnerable version lacks a check on whether the next NSB fits into the scratch buffer, the NSB chain (~174 KB of data) overflows its bounds — a classic heap buffer overflow occurs.

Researchers have demonstrated that with controlled overflow it is possible to alter the execution flow and redirect control to arbitrary shellcode with root privileges. To bypass NX protection, the mprotect() system call, described in the official man page, is used to mark a memory region as executable. This gives attackers a reliable pre-auth RCE on top of the FreeBSD base underlying NetScaler.

The vulnerability has already been added by CISA to the catalog of actively exploited vulnerabilities (Known Exploited Vulnerabilities), and details and risk assessments are also available in the NVD entry: CVE-2026-88772.

CVE-2026-88771: pre-authentication command injection

CVE-2026-88771 is an input validation vulnerability leading to remote command execution without authentication in NetScaler ADC and Gateway. It is also scored 9.5 (CVSS) and, according to analysis by the Threat Hunt Operations & Research (THOR) team at LevelBlue, is exploited via attacks on the authentication mechanism using specially crafted usernames.

LevelBlue notes the appearance in NetScaler logs of suspicious login attempts with attacker-controlled values in authentication fields containing the strings pitboss and NSPPE, which correlate with exploitation of CVE-2026-88771. After a successful command injection, attackers:

  • run test commands such as whoami;
  • use curl/wget to download secondary scripts from:
    • https://64.94.85[.]67:443/update_c08937.pl
    • http://31.56.197[.]72:9090/lula (observed more than once)
    • http://23.27.143[.]20:9000/main.py
  • extract the NetScaler configuration and archive the /flash/nsconfig directory for subsequent data exfiltration.

An overview of the vulnerability and observed exploitation artifacts is provided in the LevelBlue blog: detailed report on CVE-2026-88771, while the formal description is contained in the CVE-2026-88771 entry in NVD.

Post-exploitation toolkit: WHIPSHOT, SLAPSHOT and Perl payload

After obtaining initial access via CVE-2026-88772, attackers deploy a set of lightweight post-exploitation tools described in detail in a blog post by the Google Threat Intelligence Group (overview of attacks on NetScaler):

  • WHIPSHOT — a PHP web shell masquerading as files with .deb or .sig extensions. It extracts commands and payloads, Base64-encoded in HTTP headers, executes them, and returns the result. This allows the attackers to hide control traffic within “normal” HTTP traffic.
  • SLAPSHOT — a Python TCP tunneling tool acting as an internal network bridge. It receives commands from WHIPSHOT and forwards arbitrary TCP streams to internal hosts, facilitating reconnaissance, lateral movement and credential theft. If there is no activity for more than 10 minutes, it removes its artifacts (port, lock files) and terminates, minimizing traces.

Another identified payload, the Perl script update_c08937.pl downloaded from 64.94.85[.]67:443, performs several critical actions:

  • edits /flash/nsconfig/ns.conf, creating a local account sec_monitor with the superuser role;
  • archives /flash/nsconfig to /tmp/update_result_3567cs.tgz, sends the archive to a remote server, then deletes it and itself to reduce artifacts;
  • changes permissions on /bin/sh to 6555, effectively turning the shell into a setuid-root binary for subsequent privilege escalation;
  • deploys a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal for remote command execution and file operations;
  • modifies /etc/httpd.conf, including enabling PHP support and a URL map that mimics legitimate NetScaler CSS resources to the installed web shell.

Separately, Google notes an interesting obfuscation trick: the web server configuration is modified so that:

  • requests to /vpn/media/*.ico are redirected to the corresponding .sig files in /var/netscaler/gui/vpn/scripts/linux/;
  • these .sig files are processed as PHP scripts (after enabling mod_php).

As a result, a client requesting, for example, /vpn/media/e6ee7c85.ico is actually served by the PHP web shell e6ee7c85.sig. At the same time, logs may still show HTTP 404 responses, but with noticeably increased processing time and response body size — an indicator of hidden code execution.

Threat context and scale of exploitation

The exploit operators are not attributed to known threat groups in public reports. However, the activity bears signs of both targeted attacks (manual reconnaissance via SLAPSHOT, creation of superusers, selective theft of configurations) and mass campaigns.

According to GreyNoise data (cited in the original material), on 28 September 2026, shortly after 8:30 EDT, a phase of mass NetScaler scanning for CVE-2026-88771 and CVE-2026-88772 was recorded, and by 22:30 the same day this had grown into large-scale exploitation by numerous independent actors. Targets range from:

  • recruitment into botnets;
  • access brokerage (selling entry points to other criminal groups);
  • to deep infrastructure compromise with long-term persistence.

Google Threat Intelligence and Mandiant report compromise of dozens of organizations in the public sector, finance, technology, education, legal and professional services. A particular feature of NetScaler as an edge device is that it often lies outside the coverage of typical EDR solutions while simultaneously handling sensitive credentials, which makes it an attractive initial access point for subsequent movement across the network.

Impact assessment for organizations

Most at risk are:

  • organizations exposing NetScaler to the internet without up-to-date patches;
  • environments where NetScaler is used as a VPN gateway and authentication point (access to domain credentials, tokens, configurations);
  • infrastructures with limited monitoring of edge devices and no centralized collection of NetScaler logs.

Consequences of inaction include:

  • full attacker control over the device with root rights, modification of configuration and firmware;
  • silent deployment of web shells and backdoors disguised as legitimate resources (.deb, .sig, .ico, pseudo-CSS);
  • export of configuration, including IP addresses of internal services, LDAP/RADIUS parameters and possibly secrets;
  • creation of hidden superusers (sec_monitor) and setuid shells (/bin/sh with permissions 6555), providing persistent presence even after partial recovery;
  • use of SLAPSHOT and similar tunnels for reconnaissance and credential theft inside the network that is invisible to most security tools.

From a business perspective, this means a risk of compromise of domain infrastructure, long-term hidden adversary presence, loss of customer data, and violations of regulatory requirements related to access management and protection of the network perimeter infrastructure.

Practical recommendations for defense and detection

1. Immediate actions (first 24 hours)

  • Install the official Citrix patches for CVE-2026-88772 and CVE-2026-88771 on all internet-exposed NetScaler ADC/Gateway appliances.
  • If updating right now is impossible:
    • consider temporarily disabling DTLS or the entire VPN functionality for external users;
    • restrict access to NetScaler via VPN/administrative IP allowlists and firewall filtering.
  • Cross-check your list of CVEs with the CISA KEV catalog (Known Exploited Vulnerabilities) and ensure vulnerable NetScaler devices are not left in operation.

2. Searching for signs of compromise

Proactive threat hunting is recommended based on the following indicators:

  • Suspicious users and authentication
    • look in NetScaler logs for login attempts with usernames containing the strings pitboss or NSPPE;
    • non-standard authentication patterns leading to the launch of a shell or system commands.
  • File system and configuration
    • presence of files:
      • /var/netscaler/logon/LogonPoint/.local_journal (PHP web shell);
      • /var/netscaler/gui/vpn/scripts/linux/*.sig and *.deb with atypical PHP code;
    • strings registering .deb or .sig as PHP scripts in /etc/httpd.conf and other web server configurations;
    • reconfiguration of /vpn/media/*.ico to execute the corresponding .sig files;
    • presence in /flash/nsconfig/ns.conf of a local sec_monitor account with superuser role;
    • permissions on /bin/sh that differ from standard (check for mode 6555).
  • Network traffic and processes
    • outbound connections to:
      • 64.94.85[.]67:443
      • 31.56.197[.]72:9090
      • 23.27.143[.]20:9000
      • 45.141.21[.]130:443 (for the Python script main.py — reverse shell);
    • long-lasting or large HTTP 404 responses to requests for /vpn/media/*.ico;
    • running Python/Perl processes, especially those related to tunneling (listening ports, unusual working directories).

3. Hardening and long-term measures

  • Implement a regular CVE-based vulnerability review process with reference to NVD:
    • CVE-2026-88772 in NVD
    • CVE-2026-88771 in NVD
  • Centralize NetScaler log collection and configure correlation based on:
    • anomalous HTTP responses (404 with large response body, slow processing);
    • changes to key configurations (ns.conf, httpd.conf);
    • creation/modification of local administrator accounts.
  • Restrict administrative access to NetScaler (management interface) to dedicated management segments only.
  • Regularly compare device file systems against a baseline state to detect the appearance of new scripts and permission changes.
  • Take into account the numerous technical exploitation details provided in the technical analysis by watchTowr and their PoC repository on GitHub when developing IDS/IPS signatures and WAF rules for DTLS traffic.

The key takeaway: NetScaler is already being actively exploited as an entry point and foothold for long-term presence in networks, so in the near term it is necessary to: update all internet-exposed Citrix NetScaler appliances to fixed versions, conduct a targeted search for the described indicators of compromise (the sec_monitor account, anomalous .sig/.deb/.ico files and httpd.conf settings, suspicious outbound connections), and if signs of attack are found, immediately take devices out of service, restore them from a trusted image, and redeploy the configuration only after thorough verification.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.