SOC Prime Bias: Critical

08 Oct 2026 06:41 UTC

CVE-2026-88771 and CVE-2026-88772 Exploited in NetScaler Attacks

Author Photo
SOC Prime Team linkedin icon Follow
CVE-2026-88771 and CVE-2026-88772 Exploited in NetScaler Attacks
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

Threat actors are exploiting zero-day vulnerabilities CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and Gateway appliances. The flaws enable remote code execution and memory corruption, allowing attackers to deploy PHP or .deb web shells for initial access and persistence. The campaign also uses advanced techniques such as log poisoning and frequent infrastructure rotation.

Investigation

Unit 42 identified pre-disclosure activity involving version fingerprinting and two separate web shell delivery techniques. Researchers uncovered a DTLS exploitation chain that drops .deb packages and a three-stage command injection process leveraging log poisoning in Perl scripts. Analysts also recovered a PHP web shell that uses RC4 encryption for C2 communications.

Mitigation

Organizations should immediately upgrade Citrix software to the latest available versions to remediate the identified vulnerabilities. Vulnerable systems should be isolated where possible, and Apache configurations should be reviewed for unauthorized modifications. Disabling PHP execution globally with php_flag engine off is also recommended as an additional hardening measure.

Response

When compromise is suspected, capture a NetScaler VPX instance snapshot, remote syslog data, and a technical support bundle. Perform a packet engine core dump and investigate unexpected outbound connections or anomalous administrative sessions. Verify the integrity of /etc/httpd.conf and inspect web-accessible directories for unauthorized or suspicious files.

Attack Flow

Detections

Possible CVE-2026-88771 (Citrix NetScaler PreAuth Command Injection) Exploitation Attempt (via webserver)

SOC Prime Team
07 Oct 2026

Possible CVE-2026-88772 (Citrix NetScaler Memory Overflow In DTLS Protocol Handling) Exploitation Attempt (via syslog)

SOC Prime Team
07 Oct 2026

Hidden File Was Created On Linux Host (via file_event)

SOC Prime Team
07 Oct 2026

IOCs (HashSha256) to detect: Zero-Day Exploitation of NetScaler Devices

SOC Prime AI Rules
07 Oct 2026

IOCs (HashMd5) to detect: Zero-Day Exploitation of NetScaler Devices

SOC Prime AI Rules
07 Oct 2026

IOCs (SourceIP) to detect: Zero-Day Exploitation of NetScaler Devices

SOC Prime AI Rules
07 Oct 2026

IOCs (DestinationIP) to detect: Zero-Day Exploitation of NetScaler Devices

SOC Prime AI Rules
07 Oct 2026

Detect Exploitation of NetScaler CVE-2026-88771 and CVE-2026-88772 Vulnerabilities [Webserver]

SOC Prime AI Rules
07 Oct 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary aims to exploit the NetScaler vulnerabilities (CVE-2026-88771/72) to gain Remote Code Execution (RCE). The attacker first attempts to identify the service using a known malicious User-Agent (pitboss PPE missed too many heartbeats). They then probe for vulnerable directories like /vpn/scripts/linux/. Finally, they attempt to upload a web shell by sending a POST request containing the signature string .deb web shell within the body to bypass traditional file-extension filters while remaining detectable by the specific signature.

  • Regression Test Script:

    #!/bin/bash
    # Simulation script to trigger the NetScaler vulnerability detection rule
    
    TARGET="http://<TARGET_IP>"
    
    echo "[+] Starting Simulation: Triggering NetScaler CVE Detection..."
    
    # 1. Trigger via User-Agent
    echo "[*] Testing User-Agent trigger..."
    curl -s -A "pitboss PPE missed too many heartbeats" "$TARGET/" > /dev/null
    
    # 2. Trigger via Suspicious Path
    echo "[*] Testing Suspicious Path trigger..."
    curl -s -A "Mozilla/5.0" "$TARGET/vpn/scripts/linux/test.php" > /dev/null
    
    # 3. Trigger via Body Keyword
    echo "[*] Testing Body Keyword trigger..."
    curl -s -X POST -A "Mozilla/5.0" 
         -d "payload=exploit_data_here_.deb web shell_end" 
         "$TARGET/admin_ui/common/css/ns/ui.css" > /dev/null
    
    echo "[+] Simulation complete. Check SIEM for alerts."
  • Cleanup Commands:

    # No persistent files are created by this simulation as it only sends network requests.
    # To clean up logs, simply wait for the log retention/rotation period.
    echo "[+] No cleanup required: Simulation was non-persistent."