Citrix NetScaler — Active Exploitation of Zero-Day Vulnerabilities for Web Shell Deployment (CVE-2026-88771, CVE-2026-88772)
Publication date: September 29, 2026
Category: News
Introduction
Cybersecurity researchers and government agencies have issued urgent warnings regarding the active, in-the-wild exploitation of multiple zero-day vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances. The attacks, detected since early September 2026, have impacted organizations across North America and Europe spanning critical sectors including government, financial services, education, legal, and professional services. The intrusions allow threat actors to bypass authentication, trigger unexpected termination of packet processing engines, and achieve root-level persistence to deploy custom web shells and TCP tunneling malware.
What is Citrix NetScaler and CVE-2026-88771 / CVE-2026-88772? (General Analysis)
Citrix NetScaler ADC (Application Delivery Controller) and NetScaler Gateway are enterprise networking infrastructure solutions designed to manage, optimize, and secure web traffic and remote access to internal corporate applications. Sitting directly at the network perimeter and exposed to the Internet without the safety net of traditional Endpoint Detection and Response (EDR) software, these devices represent highly attractive targets for attackers seeking an initial foothold into internal enterprise networks.
Security investigations have confirmed two critical flaws collectively dubbed by some researchers as “PitScaler”:
- CVE-2026-88771: An improper input validation vulnerability, classified under CWE-20, allowing an unauthenticated attacker to execute arbitrary remote commands. It holds an official CVSS v4.0 score of 9.5 (CRITICAL) with the exact vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H. It is actively tracked in CISA’s KEV catalog. - CVE-2026-88772: A memory corruption / buffer overflow vulnerability, classified under CWE-119, affecting the packet processing engine when DTLS is enabled, leading to Remote Code Execution (RCE) or Denial of Service (DoS). It carries an official CVSS v4.0 score of 9.5 (CRITICAL) with the exact vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H. It is also listed in CISA’s KEV catalog.
How Does It Work? (Technical Analysis)
The exploitation mechanism uncovered by threat intelligence teams details a sophisticated attack chain engineered for persistence and lateral movement:
- Initial Infection Flow and Auth Bypass: Attackers transmit specially malformed or fragmented record headers that induce heap memory boundary corruption within the NetScaler Packet Processing Engine (NSPPE). This diverts the control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform.
- Persistence and Privilege Escalation: Although initial exploitation grants root privileges, commands executed via web shells normally run under the lower-privileged account associated with the web server. To maintain elevated control, attackers modify permissions on the shell interpreter by asserting the setuid (
set User ID) bit on the/bin/shbinary. They also reboot appliances or restart the web server daemon to apply configuration changes. - Web Shells and Malware Families (WHIPSHOT and SLAPSHOT):
- WHIPSHOT: A PHP web shell disguised as a Debian package (
.deb) or signature file (.sig), stored within NetScaler VPN script directories (e.g.,/var/netscaler/logon/LogonPoint/custom/). Attackers modify/etc/httpd.confso that non-executable file extensions are processed as PHP, or masquerade requests as CSS/image files. The malware operates as an HTTP proxy, extracting Base64-encoded data from HTTP request headers. - SLAPSHOT: A Python-based TCP tunneling tool acting as a bridge between the compromised appliance and internal hosts. It accepts commands from WHIPSHOT, opens TCP connections to internal targets, transmits data, and self-terminates after periods of inactivity to hinder detection.
- WHIPSHOT: A PHP web shell disguised as a Debian package (
Affected Systems / Environments
The vulnerabilities directly impact the following Citrix NetScaler product versions:
- NetScaler ADC: Versions prior to 14.1-73.37, prior to 13.1-64.23, prior to 14.1-73.37 FIPS, and prior to 13.1.37.279 FIPS and NDcPP.
- NetScaler Gateway: Versions prior to 14.1-73.37 and prior to 13.1-64.23.
| CVE | Category (CWE) | Impact | CVSS | Vector (Summarized) |
|---|---|---|---|---|
| CVE-2026-88771 | CWE-20 (Improper Input Validation) | Remote Code / Command Execution | 9.5 (Critical) | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/... |
| CVE-2026-88772 | CWE-119 (Memory Corruption) | RCE / Denial of Service (DoS) | 9.5 (Critical) | CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/... |
Mitigation and Detection
Remediation
The only definitive and secure remediation measure is the immediate installation of official security updates released by Citrix. In environments where immediate patching is operationally unfeasible, administrators should apply the following temporary workarounds:
- Disable DTLS where operationally practical.
- Block inbound UDP/443 traffic upstream when DTLS is not required (note: this mitigation applies strictly to CVE-2026-88772 and does not protect against CVE-2026-88771).
Detection
Incident response teams should audit NetScaler appliances for the following Indicators of Compromise (IoCs):
- Presence of suspicious
.debor.sigfiles containing PHP code within directories such as/var/netscaler/logon/LogonPoint/custom/or/vpn/media/. - Unauthorized modifications in
/etc/httpd.confmapping non-executable file extensions (like CSS or icons) as PHP handlers, or anomalousAlias/AliasMatchentries (e.g.,.ctxs.receiver). - Inspection of
/bin/shbinary permissions to check if the setuid root bit has been asserted. - Presence of temporary files such as
/tmp/.uxdportor/tmp/.uxdlockassociated with SLAPSHOT execution. - Python processes launched with
nohupor handling Base64-encoded payloads.
Blue Team Warning: The exploitation of these flaws allows threat actors to operate with superuser privileges at the network edge, leveraging HTTP obfuscation techniques that return fake HTTP 404 responses to conceal command execution. Verifying the integrity of the underlying operating system binaries is mandatory.
Wrapping Up
The simultaneous active exploitation of zero-days CVE-2026-88771 and CVE-2026-88772 in Citrix NetScaler underscores the critical vulnerability of enterprise network perimeters. With CVSS v4.0 scores of 9.5 and inclusion in CISA’s KEV catalog, these flaws empower advanced actors to compromise edge devices, escalate to root privileges, deploy stealthy web shells (WHIPSHOT), and establish TCP tunnels (SLAPSHOT) into internal corporate networks. Prioritizing official patches and conducting rigorous configuration audits on httpd.conf and system binaries are essential steps to neutralize persistent breaches.
References
- BleepingComputer. (2026, September 29). Hackers exploit Citrix NetScaler zero-day to deploy web shells. https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/
- Cloud Software Group. (2026). Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, and related vulnerabilities (Article CTX697096). https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
- Cybersecurity and Infrastructure Security Agency (CISA). (2026). Known Exploited Vulnerabilities Catalog (CVE-2026-88771, CVE-2026-88772). https://www.cisa.gov/known-exploited-vulnerabilities-catalog