Citrix NetScaler PreAuth Command Injection CVE-2026-88771
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
A critical pre-authentication command injection flaw affects Citrix NetScaler ADC and Gateway appliances. The vulnerability stems from improper input validation in a Perl script, allowing attackers to execute arbitrary system commands with root privileges. CVE-2026-88771 has been actively exploited in the wild as a zero-day vulnerability.
Investigation
Researchers performed a differential analysis of NetScaler builds 14.1-73.30 and 14.1-73.37 to uncover the underlying flaw. They identified unsafe shell interpolation through backticks in the ns_monuploadd_err.pl script, which processes unsanitized log data. By injecting specially crafted HTTP requests into log files, attackers can introduce shell metacharacters that trigger arbitrary command execution when the vulnerable script runs.
Mitigation
Citrix has issued security updates addressing CVE-2026-88771. Organizations should immediately upgrade NetScaler ADC and Gateway appliances to version 14.1-73.37 or later, or 13.1-64.23 or later. The patch replaces unsafe shell interpolation with Perl’s list-form command execution and introduces strict regex validation for captured input strings.
Response
If suspicious log entries or unauthorized command execution are detected, affected appliances should be isolated immediately. Conduct a comprehensive forensic examination of the /var/tmp and /var/core directories to identify potential payload artifacts and core dumps. Review recent access logs for anomalous HTTP requests containing shell metacharacters or other command injection indicators.
Attack Flow
We are still updating this part.
Detections
Possible CVE-2026-88771 (Citrix NetScaler PreAuth Command Injection) Exploitation Attempt (via webserver)
Detection of Malicious Command Execution in Citrix NetScaler [Linux File Event]
Detect Citrix NetScaler PreAuth Command Injection [Webserver]
Simulation Execution
-
Attack Narrative & Commands: An adversary has successfully exploited CVE-2026-88771 on a Citrix NetScaler appliance. To verify if their automated exploit script successfully placed files in the temporary directory, they execute reconnaissance commands. The attacker runs
ls -la /var/tmp/watchTowrto list the contents of the directory and subsequently usescat /var/tmp/watchTowr/payload.shto read the contents of a dropped script. These actions are intended to trigger the specific strings defined in the detection rule. -
Regression Test Script:
#!/bin/bash # Simulation script to trigger the detection rule via specific command strings # 1. Create the target directory and dummy file to mimic the exploit environment mkdir -p /var/tmp/watchTowr echo "#!/bin/bash" > /var/tmp/watchTowr/payload.sh echo "echo 'malicious payload'" >> /var/tmp/watchTowr/payload.sh # 2. Execute the commands that match the Sigma rule detection logic echo "[+] Executing reconnaissance commands to trigger detection..." ls -la /var/tmp/watchTowr cat /var/tmp/watchTowr/payload.sh echo "[+] Simulation commands executed." -
Cleanup Commands:
# Cleanup: Remove the simulated files and directory rm -rf /var/tmp/watchTowr