- Attackers used Citrix NetScaler vulnerabilities for command execution, payload retrieval, persistence, web-shell installation and attempted exfiltration.
- The payload archived NetScaler configuration data and attempted to upload it to 64.94.85[.]67:443.
- Citrix fixed both vulnerabilities in bulletin CTX697096 on Sep 27, 2026, and CISA added them to its KEV catalog the same day.
Threat actors exploited vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway to run commands, install web shells and attempt to upload configuration data, according to findings published by LevelBlue on Sep 30, 2026.
LevelBlue observed command-execution testing, reverse-shell deployment, persistence and attempted exfiltration of NetScaler configuration data. The payload archived the /flash/nsconfig directory and attempted to upload it to 64.94.85[.]67:443.
NetScaler is a line of networking products owned by Cloud Software Group. Mandiant said dozens of organizations were impacted. CyberScoop reported that, according to GreyNoise, attackers exploited CVE-2026-88771 since at least Sep 24.
On this page
The payload enabled web shells and reverse shells
The payload changed /bin/sh permissions to 6555 and deployed a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal.
It modified the HTTP configuration to enable PHP execution and mapped the web shell to URLs resembling legitimate NetScaler CSS resources.
The newly written customsnmpd creates a TCP connection to 45.141.21[.]130 over port 443, redirects standard input, output and error to the socket, and launches an interactive shell.
LevelBlue found attacker-controlled authentication events
LevelBlue’s Threat Hunt Operations & Research team analyzed the activity across multiple customer environments and identified malicious NetScaler authentication events containing attacker-controlled usernames designed to exploit CVE-2026-88771.
The Hacker News said CVE-2026-88771 is an improper-input-validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. It carries a CVSS score of 9.5.
Citrix fixed both vulnerabilities in bulletin CTX697096 on Sep 27, 2026, and CISA added them to its KEV catalog the same day. watchTowr said there is no workaround.
LevelBlue said its team analyzed the exploitation activity across multiple customer environments. Its findings included attempted exfiltration of NetScaler configuration data.
What to do now
- Preserve evidence, check for compromise, then update every NetScaler ADC and Gateway to the fixed build.
- Rotate passwords, secrets and certificates stored on or used through the appliance, and forward NetScaler logs to your SIEM.
FAQ
What happened to Citrix NetScaler?
LevelBlue said threat actors used NetScaler vulnerabilities for command execution, payload retrieval, persistence, web-shell installation and attempted exfiltration.
Who was affected by the NetScaler attacks?
LevelBlue analyzed exploitation across multiple customer environments, and Mandiant said dozens of organizations were impacted.
Has Citrix fixed the NetScaler vulnerabilities?
Citrix fixed both vulnerabilities in bulletin CTX697096 on Sep 27, 2026. watchTowr said to update every NetScaler ADC and Gateway to the fixed build and that there is no workaround.
What did the NetScaler payload do?
It changed shell permissions, deployed a PHP web shell, enabled PHP execution, archived configuration data and attempted to upload the archive to 64.94.85[.]67:443.
Sources
- Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators, LevelBluePrimary
- Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772, watchTowrPrimary
- Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs, The Hacker News
- Citrix confirms two NetScaler RCE zero-days exploited in attacks, BleepingComputer
- Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected, CyberScoop
- NetScaler, Wikipedia
How we checked this story
| Claim | Source | Status |
|---|---|---|
| The Hacker News said threat actors were observed exploiting a critical pre-authentication command-injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway. | The Hacker News | Attributed |
| LevelBlue identified malicious NetScaler authentication events containing attacker-controlled usernames designed to exploit CVE-2026-88771. | LevelBlue, via The Hacker News | Attributed |
| The Hacker News said cVE-2026-88771 is an improper-input-validation vulnerability that could let an unauthenticated attacker execute arbitrary commands. | The Hacker News | Attributed |
| The Hacker News said cVE-2026-88771 has a CVSS score of 9.5. | The Hacker News | Attributed |
| CyberScoop reported that attackers also exploited CVE-2026-88771 since at least September 24, according to GreyNoise. | GreyNoise, via CyberScoop | Attributed |
| LevelBlue observed exploitation activity involving command execution, payload retrieval, configuration collection, reverse shells, persistence, web shells and attempted exfiltration. | LevelBlue | Confirmed |
| The payload archived NetScaler configuration data and attempted to upload it to 64.94.85[.]67:443. | LevelBlue | Confirmed |
| The payload modified HTTP configuration to enable PHP and map the web shell to URLs resembling legitimate NetScaler CSS resources. | LevelBlue | Confirmed |
| watchTowr said Citrix fixed both vulnerabilities in bulletin CTX697096 on September 27, 2026, and CISA added them to its KEV catalog the same day. | watchTowr | Confirmed |
| watchTowr said organizations should capture logs, a snapshot, a support bundle and a core dump from each exposed appliance. | watchTowr | Confirmed |
| BleepingComputer reported that two unpatched Citrix NetScaler zero-day vulnerabilities were being exploited in attacks. | BleepingComputer | Attributed |
| NetScaler products are networking tools and services owned by Cloud Software Group. | Wikipedia | Confirmed |
| levelblue.com published its report on Sep 30, 2026. | levelblue.com | Confirmed |
| watchtowr.com published its report on Sep 27, 2026. | watchtowr.com | Confirmed |
Could not verify
- Whether CVE-2026-88771 and CVE-2026-88772 were exploited by the same threat actors is not established
- How many organizations were compromised is not established
- Whether configuration data was successfully exfiltrated is not established



