INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Citrix NetScaler Flaw Exploited to Deploy Web Shells and Steal
| 2026-10-08 12:56 CRITICAL HIGH EXPLOITED VULNERABILITY PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
Hackers are exploiting CVE-2026-88771, a critical Citrix NetScaler vulnerability, to run commands, install web shells, and collect appliance configuration data. The identified entity behind the attack is LevelBlue's Threat Hunt Operations & Research (THOR) team, although no specific organisation has been attributed in either source. This attack affects approximately 45 IP addresses associated with compromised systems. The attackers exploit a pre-authentication command-injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway to execute malicious scripts designed to maintain access and send stolen files to attacker infrastructure.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-4368, CVE-2026-19490 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ww•••••.io
do•••••.do
ww•••••.com
ct•••••.receiver
47.230.•••.•••
143.198.•••.•••
23.27.•••.•••
87.224.•••.•••
re•••••.css
ma•••••.py
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
6f5a2a••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
e9fe43••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
974b69••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-4368CVE-2026-4368
CVE-2026-19490CVE-2026-19490
CVE-2026-88772CVE-2026-88772
CVE-2026-88778CVE-2026-88778
CVE-2026-3055CVE-2026-3055
CVE-2026-88771CVE-2026-88771
CVE-2026-88773CVE-2026-88773
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
EUROPE
EUROPE
BENELUX
BENELUX
technologytechnology
financefinance
legallegal
governmentgovernment
educationeducation
Incident Timeline
late 2021
Threat actors used spear-phishing to exploit Citrix NetScaler vulnerabilities, which the vendor had previously identified as being exploited multiple times.
Click on any entity below to view its context and source!
general_metric
26 times
The vendor has appeared on the agency’s list of vulnerabilities known to be exploited five times this year, and a total of 26 times since late 2021.
November 2021
Threat actors used spear-phishing to exploit Citrix vulnerabilities, which were previously flagged by CISA as actively exploited since November 2021.
Click on any entity below to view its context and source!
general_metric
26 times
Since November 2021, CISA
has flagged 26 actively exploited Citrix vulnerabilities
, including six abused by ransomware gangs.
tactic
Ransomware
Since November 2021, CISA
has flagged 26 actively exploited Citrix vulnerabilities
, including six abused by ransomware gangs.
September 24, 2026
A malicious cyber actor exploited a Citrix NetScaler Gateway zero-day vulnerability on September 24, 2026.
2026/09/24
The Dutch National Cyber Security Centre (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands warning of active exploitation of Citrix NetScaler via CVE-2026-88772.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-88772
The security flaw, along with CVE-2026-88772, was disclosed last week after reports that the Dutch National Cyber Security Centre (NCSC-NL)
reportedly sent
a pre-notification to organizations in the Netherlands that urged organizations to shut their appliances down, citing active exploitation.
target_region
Netherlands
The security flaw, along with CVE-2026-88772, was disclosed last week after reports that the Dutch National Cyber Security Centre (NCSC-NL)
reportedly sent
a pre-notification to organizations in the Netherlands that urged organizations to shut their appliances down, citing active exploitation.
organisation
the Dutch National Cyber Security Centre
The security flaw, along with CVE-2026-88772, was disclosed last week after reports that the Dutch National Cyber Security Centre (NCSC-NL)
reportedly sent
a pre-notification to organizations in the Netherlands that urged organizations to shut their appliances down, citing active exploitation.
organisation
NCSC-NL
The security flaw, along with CVE-2026-88772, was disclosed last week after reports that the Dutch National Cyber Security Centre (NCSC-NL)
reportedly sent
a pre-notification to organizations in the Netherlands that urged organizations to shut their appliances down, citing active exploitation.
September 24
Threat actors used zero-day attacks to exploit Citrix NetScaler Gateway CVE-2026-88771 and CVE-2026-88772 three days before the vulnerabilities were publicly disclosed.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-88771
Exploited in zero-day attacks
GreyNoise observed a threat actor attempting to exploit a Citrix NetScaler Gateway on September 24, three days before Citrix publicly disclosed CVE-2026-88771 and CVE-2026-88772.
vulnerability
CVE-2026-88772
Exploited in zero-day attacks
GreyNoise observed a threat actor attempting to exploit a Citrix NetScaler Gateway on September 24, three days before Citrix publicly disclosed CVE-2026-88771 and CVE-2026-88772.
organisation
GreyNoise
Exploited in zero-day attacks
GreyNoise observed a threat actor attempting to exploit a Citrix NetScaler Gateway on September 24, three days before Citrix publicly disclosed CVE-2026-88771 and CVE-2026-88772.
general_metric
88772 CVE-2026
Exploited in zero-day attacks
GreyNoise observed a threat actor attempting to exploit a Citrix NetScaler Gateway on September 24, three days before Citrix publicly disclosed CVE-2026-88771 and CVE-2026-88772.
organisation
a Citrix NetScaler Gateway
Exploited in zero-day attacks
GreyNoise observed a threat actor attempting to exploit a Citrix NetScaler Gateway on September 24, three days before Citrix publicly disclosed CVE-2026-88771 and CVE-2026-88772.
Sept. 24
GreyNoise observed an unsuccessful exploitation attempt against a Citrix NetScaler Gateway on September 24.
Click on any entity below to view its context and source!
organisation
GreyNoise
The earliest known exploitation attempt occurred Sept. 24 when GreyNoise said it observed an
unsuccessful exploitation attempt
against a Citrix NetScaler Gateway under its control for malicious activity scanning purposes.
September 27, 2026
Threat actors used spear-phishing to target Citrix users, resulting in the exploitation of eight vulnerabilities affecting NetScaler Application Delivery Controller (ADC) and NetScaler Gateway.
Click on any entity below to view its context and source!
organisation
NetScaler Gateway
On September 27, 2026, Citrix
disclosed
eight vulnerabilities affecting NetScaler Application Delivery Controller (ADC) and NetScaler Gateway.
organisation
NetScaler Application
On September 27, 2026, Citrix
disclosed
eight vulnerabilities affecting NetScaler Application Delivery Controller (ADC) and NetScaler Gateway.
September 27
Threat actors used spear-phishing to exploit previously disclosed vulnerabilities in unpatched Citrix NetScaler deployments.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
Citrix has observed exploitation against unmitigated NetScaler deployments, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
both vulnerabilities to its
Known Exploited Vulnerabilities (KEV) Catalog
on September 27.
attribution
NetScaler
Citrix has observed exploitation against unmitigated NetScaler deployments, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
both vulnerabilities to its
Known Exploited Vulnerabilities (KEV) Catalog
on September 27.
attribution
Known Exploited
Citrix has observed exploitation against unmitigated NetScaler deployments, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
both vulnerabilities to its
Known Exploited Vulnerabilities (KEV) Catalog
on September 27.
attribution
KEV
Citrix has observed exploitation against unmitigated NetScaler deployments, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
both vulnerabilities to its
Known Exploited Vulnerabilities (KEV) Catalog
on September 27.
September 30
The US government mandated FCEB agencies to secure all vulnerable Citrix appliances by September 30, following the addition of CVE-2026-88771 and CVE-2026-88772 to its KEV Catalog.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-88771
Sunday, CISA
also added
CVE-2026-88771 and CVE-2026-88772 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by September 30, as mandated by
Binding Operational Directive (BOD) 26-04
.
vulnerability
CVE-2026-88772
Sunday, CISA
also added
CVE-2026-88771 and CVE-2026-88772 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by September 30, as mandated by
Binding Operational Directive (BOD) 26-04
.
tactic
T1588.006 - Vulnerabilities
Sunday, CISA
also added
CVE-2026-88771 and CVE-2026-88772 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by September 30, as mandated by
Binding Operational Directive (BOD) 26-04
.
attribution
Known Exploited
Sunday, CISA
also added
CVE-2026-88771 and CVE-2026-88772 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by September 30, as mandated by
Binding Operational Directive (BOD) 26-04
.
attribution
KEV
Sunday, CISA
also added
CVE-2026-88771 and CVE-2026-88772 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by September 30, as mandated by
Binding Operational Directive (BOD) 26-04
.
general_metric
26 times
Sunday, CISA
also added
CVE-2026-88771 and CVE-2026-88772 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by September 30, as mandated by
Binding Operational Directive (BOD) 26-04
.
attribution
Federal Civilian Executive Branch
Sunday, CISA
also added
CVE-2026-88771 and CVE-2026-88772 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by September 30, as mandated by
Binding Operational Directive (BOD) 26-04
.
attribution
FCEB
Sunday, CISA
also added
CVE-2026-88771 and CVE-2026-88772 to its
Known Exploited Vulnerabilities (KEV) Catalog
and ordered Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by September 30, as mandated by
Binding Operational Directive (BOD) 26-04
.
Oct 01, 2026
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells.
Click on any entity below to view its context and source!
organisation
NetScaler Gateway
Ravie Lakshmanan
Oct 01, 2026
Vulnerability / Web Security
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data.
organisation
Citrix NetScaler ADC
Ravie Lakshmanan
Oct 01, 2026
Vulnerability / Web Security
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data.
organisation
Vulnerability / Web Security
Ravie Lakshmanan
Oct 01, 2026
Vulnerability / Web Security
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data.
2026/10/08
Threat actors are actively exploiting two critical Citrix NetScaler zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, to gain root access, install stealthy web shells, and move into victim networks.
Click on any entity below to view its context and source!
organisation
CVE-2026
Hackers are exploiting CVE-2026-88771, a critical Citrix NetScaler vulnerability, to run commands, install web shells, and collect appliance configuration data.
CVE-2026-88771
(CVSS score: 9.5) is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
Citrix ultimately
disclosed the flaws
on Sunday as CVE-2026-88771 and CVE-2026-88772, with some researchers dubbing the vulnerabilities "PitScaler.
Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation.
Researchers are particularly concerned about CVE-2026-88771, a command-injection vulnerability that affects all NetScaler appliances in a default configuration.
organisation
Citrix NetScaler
Hackers are exploiting CVE-2026-88771, a critical Citrix NetScaler vulnerability, to run commands, install web shells, and collect appliance configuration data.
Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation.
Palo Alto Networks said it identified more than
50,000 publicly exposed instances
of Citrix NetScaler devices potentially vulnerable to both of the zero-days as of Sunday.
organisation
NetScaler CVE-2026
Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators.
organisation
NetScaler Gateway
CVE-2026-88771 is a critical pre-authentication command-injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway.
The flaw affects NetScaler ADC and NetScaler Gateway and allows command execution before authentication.
The first affects all NetScaler ADC and NetScaler Gateway deployments with default configurations, while the second requires DTLS to be enabled (Citrix noted that DTLS is toggled on by default on VPN virtual servers).
organisation
Citrix NetScaler ADC
CVE-2026-88771 is a critical pre-authentication command-injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway.
“We recently identified critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway that led us to immediately develop and release a new version of the software that addresses the issues,” the company said in a prepared statement.
organisation
NetScaler
LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler authentication events containing attacker-controlled usernames designed to weaponize CVE-2026-88771.
Google has warned that threat actors are actively exploiting two critical Citrix NetScaler zero-day vulnerabilities to gain root access, install stealthy web shells, and move into victim networks.
Observed activities included command-execution testing, payload retrieval using curl and wget, configuration collection and staging, reverse-shell deployment, persistence mechanisms, web-shell installation, and attempted exfiltration of NetScaler configuration data.
Cybersecurity firm watchTowr later said it had verified reports that two NetScaler remote code execution zero-days were being exploited in the wild and that Citrix was preparing patches.
Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings.
For instance, the Dutch National Cyber Security Center (NCSC-NL) reportedly warned organizations in the Netherlands about two critical NetScaler zero-days without CVE IDs that allowed threat actors to place shellcode directly into memory.
organisation
LevelBlue
LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler authentication events containing attacker-controlled usernames designed to weaponize CVE-2026-88771.
LevelBlue's Threat Hunt Operations & Research (THOR) team identified active exploitation across multiple customer environments featuring malicious authentication events with attacker-controlled usernames containing pitboss and NSPPE strings.
organisation
Threat Hunt Operations & Research
LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler authentication events containing attacker-controlled usernames designed to weaponize CVE-2026-88771.
LevelBlue's Threat Hunt Operations & Research (THOR) team identified active exploitation across multiple customer environments featuring malicious authentication events with attacker-controlled usernames containing pitboss and NSPPE strings.
organisation
THOR
LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler authentication events containing attacker-controlled usernames designed to weaponize CVE-2026-88771.
LevelBlue's Threat Hunt Operations & Research (THOR) team identified active exploitation across multiple customer environments featuring malicious authentication events with attacker-controlled usernames containing pitboss and NSPPE strings.
organisation
NSPPE
"One of the most consistent characteristics across the identified events was attacker-controlled authentication data containing variations of the pitboss and NSPPE strings associated with exploitation of CVE-2026-88771," LevelBlue
said
.
LevelBlue's Threat Hunt Operations & Research (THOR) team identified active exploitation across multiple customer environments featuring malicious authentication events with attacker-controlled usernames containing pitboss and NSPPE strings.
Mandiant says the exploits bypass authentication and cause the NetScaler Packet Processing Engine (NSPPE) to terminate unexpectedly, giving attackers root-level access.
organisation
NetScaler ADC
CVE-2026-88771 is an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments, while CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled.
The flaw affects NetScaler ADC and NetScaler Gateway and allows command execution before authentication.
Recommended actions
Counter Threat Unit™ (CTU) researchers recommend that organizations identify affected NetScaler ADC and NetScaler Gateway instances in their environments, prioritize internet-facing systems, and apply Citrix security updates or mitigations as appropriate.
The first affects all NetScaler ADC and NetScaler Gateway deployments with default configurations, while the second requires DTLS to be enabled (Citrix noted that DTLS is toggled on by default on VPN virtual servers).
organisation
DTLS
CVE-2026-88771 is an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments, while CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled.
The first affects all NetScaler ADC and NetScaler Gateway deployments with default configurations, while the second requires DTLS to be enabled (Citrix noted that DTLS is toggled on by default on VPN virtual servers).
organisation
Palo Alto Networks
Palo Alto Networks said it identified more than
50,000 publicly exposed instances
of Citrix NetScaler devices potentially vulnerable to both of the zero-days as of Sunday.
organisation
Counter Threat Unit
Recommended actions
Counter Threat Unit™ (CTU) researchers recommend that organizations identify affected NetScaler ADC and NetScaler Gateway instances in their environments, prioritize internet-facing systems, and apply Citrix security updates or mitigations as appropriate.
organisation
Cyber Security News
[…] The post Hackers Exploit Critical Citrix NetScaler Flaw to Deploy Web Shells and Steal Configuration Data appeared first on Cyber Security News .
Mandiant Consulting and Google Threat Intelligence Group […] The post Google Warns of Hackers Actively Exploiting Citrix 0-Day Vulnerabilities to Deploy Web Shells appeared first on Cyber Security News .
organisation
Mandiant Consulting
Mandiant Consulting and Google Threat Intelligence Group […] The post Google Warns of Hackers Actively Exploiting Citrix 0-Day Vulnerabilities to Deploy Web Shells appeared first on Cyber Security News .
organisation
Google
Google has warned that threat actors are actively exploiting two critical Citrix NetScaler zero-day vulnerabilities to gain root access, install stealthy web shells, and move into victim networks.
Google observed similar post-exploitation activity in intrusions, including attackers installing PHP web shells and modified the NetScaler web server configuration so non-executable file extensions would process them as PHP.
organisation
NCSC-NL
For instance, the Dutch National Cyber Security Center (NCSC-NL) reportedly warned organizations in the Netherlands about two critical NetScaler zero-days without CVE IDs that allowed threat actors to place shellcode directly into memory.
organisation
the Dutch National Cyber Security Center
For instance, the Dutch National Cyber Security Center (NCSC-NL) reportedly warned organizations in the Netherlands about two critical NetScaler zero-days without CVE IDs that allowed threat actors to place shellcode directly into memory.
organisation
IP
The attacker, using IP address 149.104.78.141, attempted exploitation that was detected through behavioral analysis despite no CVE-specific signatures existing at the time.
"
Currently, threat watchdog Shadowserver tracks over 23,000 IP addresses with NetScaler fingerprints exposed on the Internet (including
nearly 22,000 NetScaler ADC
appliances and
just over 1,500 Gateway
instances).
infrastructure
23,000 IP addresses
"
Currently, threat watchdog Shadowserver tracks over 23,000 IP addresses with NetScaler fingerprints exposed on the Internet (including
nearly 22,000 NetScaler ADC
appliances and
just over 1,500 Gateway
instances).
organisation
PHP
The attacker tried to configure the web server to execute a hidden PHP webshell disguised as a CSS file, using aliases to route requests.
Analysis revealed two second-stage payloads: main.py establishing reverse shells to command-and-control infrastructure, and update_c08937.pl creating privileged accounts, deploying PHP web shells, and attempting configuration exfiltration.
Change the permissions of "/bin/sh" to 6555 and deploy a PHP web shell at "/var/netscaler/logon/LogonPoint/.local_journal" for remote command execution and file upload and download.
/sh
to give a root shell and install a password-protected PHP web shell at
/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver
.
organisation
CSS
The attacker tried to configure the web server to execute a hidden PHP webshell disguised as a CSS file, using aliases to route requests.
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs.
The attacker also attempted to modify
/etc/httpd.conf
so requests for what appeared to be CSS files, including
receiver.min.css
, would instead open the hidden PHP web shell.
organisation
/etc/httpd.conf
The attacker also attempted to modify
/etc/httpd.conf
so requests for what appeared to be CSS files, including
receiver.min.css
, would instead open the hidden PHP web shell.
infrastructure
64.94.85
Other attempts have been observed using curl or wget to fetch additional payloads from external servers, or extract NetScaler configuration data -
64.94.85[.]67:443/update_c08937.pl
31.56.197[.]72:9090/lula
23.27.143[.]20:9000/main.py
"Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation," LevelBlue said.
Archive the "/flash/nsconfig" directory into "/tmp/update_result_3567cs.tgz" and upload the resulting archive containing NetScaler configuration data to "64.94.85[.]67:443."
infrastructure
31.56.197
Other attempts have been observed using curl or wget to fetch additional payloads from external servers, or extract NetScaler configuration data -
64.94.85[.]67:443/update_c08937.pl
31.56.197[.]72:9090/lula
23.27.143[.]20:9000/main.py
"Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation," LevelBlue said.
infrastructure
23.27.143
Other attempts have been observed using curl or wget to fetch additional payloads from external servers, or extract NetScaler configuration data -
64.94.85[.]67:443/update_c08937.pl
31.56.197[.]72:9090/lula
23.27.143[.]20:9000/main.py
"Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation," LevelBlue said.
organisation
Citrix NetScaler Gateway
“We recently identified critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway that led us to immediately develop and release a new version of the software that addresses the issues,” the company said in a prepared statement.
organisation
Mandiant
Mandiant says the exploits bypass authentication and cause the NetScaler Packet Processing Engine (NSPPE) to terminate unexpectedly, giving attackers root-level access.
organisation
the NetScaler Packet Processing Engine
Mandiant says the exploits bypass authentication and cause the NetScaler Packet Processing Engine (NSPPE) to terminate unexpectedly, giving attackers root-level access.
organisation
CVSS
The critical defects are both rated 9.5 on the CVSS scale and allow attackers to achieve remote code execution.
The remaining six vulnerabilities (CVE-2026-88773 through CVE-2026-88778) have been assigned CVSS scores ranging from 7.0 to 9.3.
organisation
TCP
SLAPSHOT is a Python-based TCP tunneling tool that bridges the compromised NetScaler appliance and internal devices, allowing attackers to spread further into the network.
"These vulnerabilities vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions.
Exploitation of these issues can result in HTTP request smuggling, policy bypass, denial of service, and TCP sequence number prediction.
organisation
Modify
Another second-stage payload, "update_c08937.pl," is a Perl script with several post-exploitation capabilities -
Modify "/flash/nsconfig/ns.conf" to create a local account named sec_monitor and assign it the superuser role.
organisation
NetScaler CSS
Modify "/etc/httpd.conf" to enable PHP execution and map the web shell to URLs resembling legitimate NetScaler CSS resources, corroborating activity
observed
by GreyNoise.
organisation
GreyNoise
Modify "/etc/httpd.conf" to enable PHP execution and map the web shell to URLs resembling legitimate NetScaler CSS resources, corroborating activity
observed
by GreyNoise.
organisation
AliasMatch
Commands used to deploy a PHP web shell on NetScaler
Source: GreyNoise
The company is not publishing the full exploit for now, but recommends defenders hunt for the
.ctxs.receiver
file, related
Alias
or
AliasMatch
entries in httpd.conf, changes to the permissions of /bin/sh, and connections from the observed source IP.
organisation
/bin/sh
Commands used to deploy a PHP web shell on NetScaler
Source: GreyNoise
The company is not publishing the full exploit for now, but recommends defenders hunt for the
.ctxs.receiver
file, related
Alias
or
AliasMatch
entries in httpd.conf, changes to the permissions of /bin/sh, and connections from the observed source IP.
organisation
EDR
NetScaler ADC and Gateway appliances are attractive targets because they are exposed to the Internet and often sit at the edge of internal networks, without having the same benefit of EDR software.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CyberScoop
Customers were receiving warnings through unofficial channels while Citrix remained publicly silent,” Ben Harris, founder and CEO at watchTowr, told CyberScoop.
organisation
NetScaler Console
Citrix has made indicators of compromise available through NetScaler Console and published additional guidance.
Tactical Metrics
Metrics
infrastructure
64.94.85
Software Version
Click for context!
Other attempts have been observed using curl or wget to fetch additional payloads from external servers, or extract NetScaler configuration data -
64.94.85[.]67:443/update_c08937.pl
31.56.197[.]72:9090/lula
23.27.143[.]20:9000/main.py
"Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation," LevelBlue said.
Archive the "/flash/nsconfig" directory into "/tmp/update_result_3567cs.tgz" and upload the resulting archive containing NetScaler configuration data to "64.94.85[.]67:443."
Metrics
infrastructure
31.56.197
Software Version
Other attempts have been observed using curl or wget to fetch additional payloads from external servers, or extract NetScaler configuration data -
64.94.85[.]67:443/update_c08937.pl
31.56.197[.]72:9090/lula
23.27.143[.]20:9000/main.py
"Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation," LevelBlue said.
Metrics
infrastructure
23.27.143
Software Version
Other attempts have been observed using curl or wget to fetch additional payloads from external servers, or extract NetScaler configuration data -
64.94.85[.]67:443/update_c08937.pl
31.56.197[.]72:9090/lula
23.27.143[.]20:9000/main.py
"Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation," LevelBlue said.
Metrics
infrastructure
23,000
Ip Addresses
"
Currently, threat watchdog Shadowserver tracks over 23,000 IP addresses with NetScaler fingerprints exposed on the Internet (including
nearly 22,000 NetScaler ADC
appliances and
just over 1,500 Gateway
instances).
Intelligence Sources
BleepingComputer
2026-09-29
Hackers exploit Citrix NetScaler zero-day to deploy web shells
BleepingComputer
BleepingComputer
2026-09-28
CISA orders feds to patch exploited Citrix flaws by Wednesday
BleepingComputer
Sophos News
2026-09-28
CyberScoop
2026-09-29
AlienVault OTX
2026-09-30
The Hacker News
2026-10-01
AlienVault OTX
2026-10-01
AlienVault OTX
2026-10-01
Swarming Against Citrix 0-Day Exploitation
AlienVault OTX
AlienVault OTX
2026-09-29
AlienVault OTX
2026-10-08
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-09T06:32
Comprehensive Tactical Telemetry
Highly Correlated Entities
44x
organisation
Identified Entity
CVE-2026
entity
18x
attribution
Attributing Entity
Google Threat Intelligence Group
authority
11x
timeline
Temporal Reference
September 24, 2026
date
7x
vulnerability
Exploited CVE
CVE-2026-88771
cve
5x
tactic
Cyber Operation Type
Exfiltration
tactic
4x
industry
Targeted Sector
Government
sector
3x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
3x
infrastructure
Software Version
64.94.85
version
2x
general metric
Cve-2026
88,771
cve-2026
2x
target region
Target Region
EUROPE
region
Contextual Telemetry
Context Block
15 METRICS
general metric
Day
0
day
target region
Target Country
Netherlands
country
general metric
Score
10
score
general metric
Tcp Port
443
tcp port
general metric
Fake Responses
404
fake responses
vulnerability
CVSS Score
10
score
general metric
Remaining Vulnerabilities
88,778
remaining vulnerabilities
source region
Origin Country
United States
country
general metric
Exposed Instances
50,000
exposed instances
general metric
Times
26
times
general metric
Hours
36
hours
general metric
Citrixbleed
2
citrixbleed
infrastructure
Ip Addresses
23,000
ip addresses
general metric
Netscaler Adc Appliances
22,000
netscaler adc appliances
general metric
Gateway Instances
1,500
gateway instances
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.