Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)
Unit 42 reports possible zero-day exploitation of Citrix NetScaler devices through CVE-2026-88771 and CVE-2026-88772, with attackers using the flaws to deploy web shells and gain persistence. The activity involved infrastructure linked to fingerprinting, DTLS exploitation, and a three-stage command-injection chain, while Citrix and Palo Alto Networks observed widespread exposure and post-disclosure scanning. #Citrix #NetScaler #CVE-2026-88771 #CVE-2026-88772 #Unit42

Keypoints

  • Unit 42 identified possible zero-day exploitation against Citrix NetScaler devices involving CVE-2026-88771 and CVE-2026-88772.
  • Threat actors used the vulnerabilities to deliver web shells, establish initial access, and maintain persistence in targeted organizations.
  • As of Sept. 27, 2026, Cortex Xpanse identified 50,277 exposed instances that could potentially be vulnerable.
  • Two pre-disclosure activity patterns were observed: DTLS exploitation that dropped .deb web shells and a three-stage command-injection chain that deployed PHP web shells.
  • The attackers used rotating infrastructure, including VPS hosts, Cloudflare WARP VPN addresses, and multiple IPs, to request files and interact with appliances.
  • Post-exploitation tooling included RC4-encrypted PHP web shells that supported command execution, file upload, and file exfiltration.
  • Citrix device compromise included log poisoning, Apache config tampering, PHP engine enablement, and web shell masking through CSS-like aliases.

MITRE Techniques

  • [T1190] Exploit Public-Facing Application – Attackers exploited NetScaler devices via CVE-2026-88771 and CVE-2026-88772 to gain access (‘have been exploited in the wild’ / ‘delivered web shells and establish their initial access’).
  • [T1059.004] Command and Scripting Interpreter: Unix Shell – The web shell and exploit chain executed shell commands through functions like exec, passthru, system, and piping decoded payloads to sh (‘runs that text as part of a shell command’ / ‘pipes it to sh or php’).
  • [T1059.006] Command and Scripting Interpreter: Python? – Not mentioned.
  • [T1505.003] Server Software Component: Web Shell – The attackers dropped PHP and .deb-based web shells on NetScaler appliances for remote control (‘deliver web shells’ / ‘Deploy the PHP Web Shell’).
  • [T1003] OS Credential Dumping – Not mentioned.
  • [T1071.001] Application Layer Protocol: Web Protocols – The shell communicated over HTTP, using cookies, headers, and URL requests as its command channel (‘Actor commands arrive through a custom HTTP headers’ / ‘NSC_TASS cookie carries the URL-encoded command’).
  • [T1027] Obfuscated Files or Information – The payload was Base64-encoded and RC4-encrypted to hide commands and content (‘encoded as Base64 text’ / ‘All command-and-control communication is RC4-encrypted’).
  • [T1105] Ingress Tool Transfer – Malicious payloads and web shells were delivered to the appliance via staged requests and dropped files (‘drops PHP web shells’ / ‘dropped and executed as a Base64 payload’).
  • [T1565.001] Data Manipulation: Stored Data Manipulation – The attacker poisoned logs to trigger later command execution via log processing (‘logged as a failure message’ / ‘picks up the poisoned log entries’).
  • [T1055] Process Injection – Not mentioned.
  • [T1562.001] Impair Defenses: Disable or Modify Tools – The attacker modified Apache configuration and enabled PHP execution (‘patching /etc/httpd.conf’ / ‘php_flag engine on’).
  • [T1098] Account Manipulation – Not mentioned.
  • [T1543.002] Create or Modify System Process: Systemd Service – Not mentioned.
  • [T1547.001] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder – Not mentioned.
  • [T1546.006] Event Triggered Execution: LC_LOAD_DYLIB – Not mentioned.
  • [T1106] Native API – Not mentioned.

Indicators of Compromise

  • [IP address] Suspected scanning/exploitation infrastructure – 104.248.244[.]66, 77.83.199[.]39, and 193.149.176[.]207
  • [IP address] Additional network indicators tied to the activity – 104.28.247[.]136, 104.28.215[.]137, and 162.33.178[.]9
  • [File path] Web shell and payload locations on NetScaler systems – /vpn/scripts/linux/nsg64.deb, /vpn/scripts/linux/nsgclient18.deb, and /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver
  • [SHA-256 hash] Malicious payload and shell samples – 1bd314b661396c7086f6367fbbb48025e03ca2de69c073d53a8b0a38aa5fbb7d, 79c65fa04541032e251fa4796b97800374b63c7982593dd1a2e0db605d429186, and ae22ef2517b5c0fb47f78745b9cb5260acee0e751b89bcd354640ff8bc8d29ec
  • [File name] Malicious or dropped files – nsg64.deb, nsgclient18.deb, nsgser18.deb, nsgsupport.deb, and nsgpackage64.deb
  • [URL path] Suspicious requested or abused endpoints – /admin_ui/common/css/ns/ui.css, /vpn/js/rdx/core/lang/rdx_en.json.gz, and /logon/LogonPoint/Authentication/GetUserName


Read more: https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/