// AI threat desk · 4 Oct 2026
Home/CVE · Vulns & Patches
Vulns & PatchesCriticalCVECVSS 9.5

Citrix NetScaler vulnerabilities exploited to deploy web shells

The Hacker News said CVE-2026-88771 could let an unauthenticated attacker execute commands and has a CVSS score of 9.5.

AI-generated image of hands examining a network appliance and a blurred cybersecurity incident dashboard in a server room.
AI-generated image, not a photo of the event.
Key takeaways
  • Attackers used Citrix NetScaler vulnerabilities for command execution, payload retrieval, persistence, web-shell installation and attempted exfiltration.
  • The payload archived NetScaler configuration data and attempted to upload it to 64.94.85[.]67:443.
  • Citrix fixed both vulnerabilities in bulletin CTX697096 on Sep 27, 2026, and CISA added them to its KEV catalog the same day.

Threat actors exploited vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway to run commands, install web shells and attempt to upload configuration data, according to findings published by LevelBlue on Sep 30, 2026.

LevelBlue observed command-execution testing, reverse-shell deployment, persistence and attempted exfiltration of NetScaler configuration data. The payload archived the /flash/nsconfig directory and attempted to upload it to 64.94.85[.]67:443.

NetScaler is a line of networking products owned by Cloud Software Group. Mandiant said dozens of organizations were impacted. CyberScoop reported that, according to GreyNoise, attackers exploited CVE-2026-88771 since at least Sep 24.

On this page

The payload enabled web shells and reverse shells

The payload changed /bin/sh permissions to 6555 and deployed a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal.

It modified the HTTP configuration to enable PHP execution and mapped the web shell to URLs resembling legitimate NetScaler CSS resources.

The newly written customsnmpd creates a TCP connection to 45.141.21[.]130 over port 443, redirects standard input, output and error to the socket, and launches an interactive shell.

LevelBlue found attacker-controlled authentication events

LevelBlue’s Threat Hunt Operations & Research team analyzed the activity across multiple customer environments and identified malicious NetScaler authentication events containing attacker-controlled usernames designed to exploit CVE-2026-88771.

The Hacker News said CVE-2026-88771 is an improper-input-validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. It carries a CVSS score of 9.5.

Citrix fixed both vulnerabilities in bulletin CTX697096 on Sep 27, 2026, and CISA added them to its KEV catalog the same day. watchTowr said there is no workaround.

LevelBlue said its team analyzed the exploitation activity across multiple customer environments. Its findings included attempted exfiltration of NetScaler configuration data.

What to do now

  1. Preserve evidence, check for compromise, then update every NetScaler ADC and Gateway to the fixed build.
  2. Rotate passwords, secrets and certificates stored on or used through the appliance, and forward NetScaler logs to your SIEM.

FAQ

What happened to Citrix NetScaler?

LevelBlue said threat actors used NetScaler vulnerabilities for command execution, payload retrieval, persistence, web-shell installation and attempted exfiltration.

Who was affected by the NetScaler attacks?

LevelBlue analyzed exploitation across multiple customer environments, and Mandiant said dozens of organizations were impacted.

Has Citrix fixed the NetScaler vulnerabilities?

Citrix fixed both vulnerabilities in bulletin CTX697096 on Sep 27, 2026. watchTowr said to update every NetScaler ADC and Gateway to the fixed build and that there is no workaround.

What did the NetScaler payload do?

It changed shell permissions, deployed a PHP web shell, enabled PHP execution, archived configuration data and attempted to upload the archive to 64.94.85[.]67:443.

Sources

  1. Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators, LevelBluePrimary
  2. Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772, watchTowrPrimary
  3. Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs, The Hacker News
  4. Citrix confirms two NetScaler RCE zero-days exploited in attacks, BleepingComputer
  5. Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected, CyberScoop
  6. NetScaler, Wikipedia
How we checked this story
ClaimSourceStatus
The Hacker News said threat actors were observed exploiting a critical pre-authentication command-injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway.The Hacker NewsAttributed
LevelBlue identified malicious NetScaler authentication events containing attacker-controlled usernames designed to exploit CVE-2026-88771.LevelBlue, via The Hacker NewsAttributed
The Hacker News said cVE-2026-88771 is an improper-input-validation vulnerability that could let an unauthenticated attacker execute arbitrary commands.The Hacker NewsAttributed
The Hacker News said cVE-2026-88771 has a CVSS score of 9.5.The Hacker NewsAttributed
CyberScoop reported that attackers also exploited CVE-2026-88771 since at least September 24, according to GreyNoise.GreyNoise, via CyberScoopAttributed
LevelBlue observed exploitation activity involving command execution, payload retrieval, configuration collection, reverse shells, persistence, web shells and attempted exfiltration.LevelBlueConfirmed
The payload archived NetScaler configuration data and attempted to upload it to 64.94.85[.]67:443.LevelBlueConfirmed
The payload modified HTTP configuration to enable PHP and map the web shell to URLs resembling legitimate NetScaler CSS resources.LevelBlueConfirmed
watchTowr said Citrix fixed both vulnerabilities in bulletin CTX697096 on September 27, 2026, and CISA added them to its KEV catalog the same day.watchTowrConfirmed
watchTowr said organizations should capture logs, a snapshot, a support bundle and a core dump from each exposed appliance.watchTowrConfirmed
BleepingComputer reported that two unpatched Citrix NetScaler zero-day vulnerabilities were being exploited in attacks.BleepingComputerAttributed
NetScaler products are networking tools and services owned by Cloud Software Group.WikipediaConfirmed
levelblue.com published its report on Sep 30, 2026.levelblue.comConfirmed
watchtowr.com published its report on Sep 27, 2026.watchtowr.comConfirmed

Could not verify

  • Whether CVE-2026-88771 and CVE-2026-88772 were exploited by the same threat actors is not established
  • How many organizations were compromised is not established
  • Whether configuration data was successfully exfiltrated is not established
Explore with AI