Citrix NetScaler — Active Exploitation of Zero-Day Vulnerabilities for Web Shell Deployment (CVE-2026-88771, CVE-2026-88772)

Publication date: September 29, 2026
Category: News

Introduction

Cybersecurity researchers and government agencies have issued urgent warnings regarding the active, in-the-wild exploitation of multiple zero-day vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances. The attacks, detected since early September 2026, have impacted organizations across North America and Europe spanning critical sectors including government, financial services, education, legal, and professional services. The intrusions allow threat actors to bypass authentication, trigger unexpected termination of packet processing engines, and achieve root-level persistence to deploy custom web shells and TCP tunneling malware.

What is Citrix NetScaler and CVE-2026-88771 / CVE-2026-88772? (General Analysis)

Citrix NetScaler ADC (Application Delivery Controller) and NetScaler Gateway are enterprise networking infrastructure solutions designed to manage, optimize, and secure web traffic and remote access to internal corporate applications. Sitting directly at the network perimeter and exposed to the Internet without the safety net of traditional Endpoint Detection and Response (EDR) software, these devices represent highly attractive targets for attackers seeking an initial foothold into internal enterprise networks.

Security investigations have confirmed two critical flaws collectively dubbed by some researchers as “PitScaler”:

  • CVE-2026-88771: An improper input validation vulnerability, classified under CWE-20, allowing an unauthenticated attacker to execute arbitrary remote commands. It holds an official CVSS v4.0 score of 9.5 (CRITICAL) with the exact vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H. It is actively tracked in CISA’s KEV catalog.
  • CVE-2026-88772: A memory corruption / buffer overflow vulnerability, classified under CWE-119, affecting the packet processing engine when DTLS is enabled, leading to Remote Code Execution (RCE) or Denial of Service (DoS). It carries an official CVSS v4.0 score of 9.5 (CRITICAL) with the exact vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H. It is also listed in CISA’s KEV catalog.

How Does It Work? (Technical Analysis)

The exploitation mechanism uncovered by threat intelligence teams details a sophisticated attack chain engineered for persistence and lateral movement:

  • Initial Infection Flow and Auth Bypass: Attackers transmit specially malformed or fragmented record headers that induce heap memory boundary corruption within the NetScaler Packet Processing Engine (NSPPE). This diverts the control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform.
  • Persistence and Privilege Escalation: Although initial exploitation grants root privileges, commands executed via web shells normally run under the lower-privileged account associated with the web server. To maintain elevated control, attackers modify permissions on the shell interpreter by asserting the setuid (set User ID) bit on the /bin/sh binary. They also reboot appliances or restart the web server daemon to apply configuration changes.
  • Web Shells and Malware Families (WHIPSHOT and SLAPSHOT):
    • WHIPSHOT: A PHP web shell disguised as a Debian package (.deb) or signature file (.sig), stored within NetScaler VPN script directories (e.g., /var/netscaler/logon/LogonPoint/custom/). Attackers modify /etc/httpd.conf so that non-executable file extensions are processed as PHP, or masquerade requests as CSS/image files. The malware operates as an HTTP proxy, extracting Base64-encoded data from HTTP request headers.
    • SLAPSHOT: A Python-based TCP tunneling tool acting as a bridge between the compromised appliance and internal hosts. It accepts commands from WHIPSHOT, opens TCP connections to internal targets, transmits data, and self-terminates after periods of inactivity to hinder detection.

Affected Systems / Environments

The vulnerabilities directly impact the following Citrix NetScaler product versions:

  • NetScaler ADC: Versions prior to 14.1-73.37, prior to 13.1-64.23, prior to 14.1-73.37 FIPS, and prior to 13.1.37.279 FIPS and NDcPP.
  • NetScaler Gateway: Versions prior to 14.1-73.37 and prior to 13.1-64.23.
CVE Category (CWE) Impact CVSS Vector (Summarized)
CVE-2026-88771 CWE-20 (Improper Input Validation) Remote Code / Command Execution 9.5 (Critical) CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/...
CVE-2026-88772 CWE-119 (Memory Corruption) RCE / Denial of Service (DoS) 9.5 (Critical) CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/...

Mitigation and Detection

Remediation

The only definitive and secure remediation measure is the immediate installation of official security updates released by Citrix. In environments where immediate patching is operationally unfeasible, administrators should apply the following temporary workarounds:

  • Disable DTLS where operationally practical.
  • Block inbound UDP/443 traffic upstream when DTLS is not required (note: this mitigation applies strictly to CVE-2026-88772 and does not protect against CVE-2026-88771).

Detection

Incident response teams should audit NetScaler appliances for the following Indicators of Compromise (IoCs):

  • Presence of suspicious .deb or .sig files containing PHP code within directories such as /var/netscaler/logon/LogonPoint/custom/ or /vpn/media/.
  • Unauthorized modifications in /etc/httpd.conf mapping non-executable file extensions (like CSS or icons) as PHP handlers, or anomalous Alias / AliasMatch entries (e.g., .ctxs.receiver).
  • Inspection of /bin/sh binary permissions to check if the setuid root bit has been asserted.
  • Presence of temporary files such as /tmp/.uxdport or /tmp/.uxdlock associated with SLAPSHOT execution.
  • Python processes launched with nohup or handling Base64-encoded payloads.

Blue Team Warning: The exploitation of these flaws allows threat actors to operate with superuser privileges at the network edge, leveraging HTTP obfuscation techniques that return fake HTTP 404 responses to conceal command execution. Verifying the integrity of the underlying operating system binaries is mandatory.

Wrapping Up

The simultaneous active exploitation of zero-days CVE-2026-88771 and CVE-2026-88772 in Citrix NetScaler underscores the critical vulnerability of enterprise network perimeters. With CVSS v4.0 scores of 9.5 and inclusion in CISA’s KEV catalog, these flaws empower advanced actors to compromise edge devices, escalate to root privileges, deploy stealthy web shells (WHIPSHOT), and establish TCP tunnels (SLAPSHOT) into internal corporate networks. Prioritizing official patches and conducting rigorous configuration audits on httpd.conf and system binaries are essential steps to neutralize persistent breaches.

References