Unit 42 reports possible zero-day exploitation of Citrix NetScaler devices through CVE-2026-88771 and CVE-2026-88772, with attackers using the flaws to deploy web shells and gain persistence. The activity involved infrastructure linked to fingerprinting, DTLS exploitation, and a three-stage command-injection chain, while Citrix and Palo Alto Networks observed widespread exposure and post-disclosure scanning. #Citrix #NetScaler #CVE-2026-88771 #CVE-2026-88772 #Unit42
Keypoints
- Unit 42 identified possible zero-day exploitation against Citrix NetScaler devices involving CVE-2026-88771 and CVE-2026-88772.
- Threat actors used the vulnerabilities to deliver web shells, establish initial access, and maintain persistence in targeted organizations.
- As of Sept. 27, 2026, Cortex Xpanse identified 50,277 exposed instances that could potentially be vulnerable.
- Two pre-disclosure activity patterns were observed: DTLS exploitation that dropped .deb web shells and a three-stage command-injection chain that deployed PHP web shells.
- The attackers used rotating infrastructure, including VPS hosts, Cloudflare WARP VPN addresses, and multiple IPs, to request files and interact with appliances.
- Post-exploitation tooling included RC4-encrypted PHP web shells that supported command execution, file upload, and file exfiltration.
- Citrix device compromise included log poisoning, Apache config tampering, PHP engine enablement, and web shell masking through CSS-like aliases.
MITRE Techniques
- [T1190] Exploit Public-Facing Application â Attackers exploited NetScaler devices via CVE-2026-88771 and CVE-2026-88772 to gain access (âhave been exploited in the wildâ / âdelivered web shells and establish their initial accessâ).
- [T1059.004] Command and Scripting Interpreter: Unix Shell â The web shell and exploit chain executed shell commands through functions like exec, passthru, system, and piping decoded payloads to sh (âruns that text as part of a shell commandâ / âpipes it to sh or phpâ).
- [T1059.006] Command and Scripting Interpreter: Python? â Not mentioned.
- [T1505.003] Server Software Component: Web Shell â The attackers dropped PHP and .deb-based web shells on NetScaler appliances for remote control (âdeliver web shellsâ / âDeploy the PHP Web Shellâ).
- [T1003] OS Credential Dumping â Not mentioned.
- [T1071.001] Application Layer Protocol: Web Protocols â The shell communicated over HTTP, using cookies, headers, and URL requests as its command channel (âActor commands arrive through a custom HTTP headersâ / âNSC_TASS cookie carries the URL-encoded commandâ).
- [T1027] Obfuscated Files or Information â The payload was Base64-encoded and RC4-encrypted to hide commands and content (âencoded as Base64 textâ / âAll command-and-control communication is RC4-encryptedâ).
- [T1105] Ingress Tool Transfer â Malicious payloads and web shells were delivered to the appliance via staged requests and dropped files (âdrops PHP web shellsâ / âdropped and executed as a Base64 payloadâ).
- [T1565.001] Data Manipulation: Stored Data Manipulation â The attacker poisoned logs to trigger later command execution via log processing (âlogged as a failure messageâ / âpicks up the poisoned log entriesâ).
- [T1055] Process Injection â Not mentioned.
- [T1562.001] Impair Defenses: Disable or Modify Tools â The attacker modified Apache configuration and enabled PHP execution (âpatching /etc/httpd.confâ / âphp_flag engine onâ).
- [T1098] Account Manipulation â Not mentioned.
- [T1543.002] Create or Modify System Process: Systemd Service â Not mentioned.
- [T1547.001] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder â Not mentioned.
- [T1546.006] Event Triggered Execution: LC_LOAD_DYLIB â Not mentioned.
- [T1106] Native API â Not mentioned.
Indicators of Compromise
- [IP address] Suspected scanning/exploitation infrastructure â 104.248.244[.]66, 77.83.199[.]39, and 193.149.176[.]207
- [IP address] Additional network indicators tied to the activity â 104.28.247[.]136, 104.28.215[.]137, and 162.33.178[.]9
- [File path] Web shell and payload locations on NetScaler systems â /vpn/scripts/linux/nsg64.deb, /vpn/scripts/linux/nsgclient18.deb, and /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver
- [SHA-256 hash] Malicious payload and shell samples â 1bd314b661396c7086f6367fbbb48025e03ca2de69c073d53a8b0a38aa5fbb7d, 79c65fa04541032e251fa4796b97800374b63c7982593dd1a2e0db605d429186, and ae22ef2517b5c0fb47f78745b9cb5260acee0e751b89bcd354640ff8bc8d29ec
- [File name] Malicious or dropped files â nsg64.deb, nsgclient18.deb, nsgser18.deb, nsgsupport.deb, and nsgpackage64.deb
- [URL path] Suspicious requested or abused endpoints â /admin_ui/common/css/ns/ui.css, /vpn/js/rdx/core/lang/rdx_en.json.gz, and /logon/LogonPoint/Authentication/GetUserName
Read more: https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/