CVE-2026-88771 and CVE-2026-88772 Exploited in NetScaler Attacks
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
Threat actors are exploiting zero-day vulnerabilities CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and Gateway appliances. The flaws enable remote code execution and memory corruption, allowing attackers to deploy PHP or .deb web shells for initial access and persistence. The campaign also uses advanced techniques such as log poisoning and frequent infrastructure rotation.
Investigation
Unit 42 identified pre-disclosure activity involving version fingerprinting and two separate web shell delivery techniques. Researchers uncovered a DTLS exploitation chain that drops .deb packages and a three-stage command injection process leveraging log poisoning in Perl scripts. Analysts also recovered a PHP web shell that uses RC4 encryption for C2 communications.
Mitigation
Organizations should immediately upgrade Citrix software to the latest available versions to remediate the identified vulnerabilities. Vulnerable systems should be isolated where possible, and Apache configurations should be reviewed for unauthorized modifications. Disabling PHP execution globally with php_flag engine off is also recommended as an additional hardening measure.
Response
When compromise is suspected, capture a NetScaler VPX instance snapshot, remote syslog data, and a technical support bundle. Perform a packet engine core dump and investigate unexpected outbound connections or anomalous administrative sessions. Verify the integrity of /etc/httpd.conf and inspect web-accessible directories for unauthorized or suspicious files.
Attack Flow
Detections
Possible CVE-2026-88771 (Citrix NetScaler PreAuth Command Injection) Exploitation Attempt (via webserver)
Possible CVE-2026-88772 (Citrix NetScaler Memory Overflow In DTLS Protocol Handling) Exploitation Attempt (via syslog)
Hidden File Was Created On Linux Host (via file_event)
IOCs (HashSha256) to detect: Zero-Day Exploitation of NetScaler Devices
IOCs (HashMd5) to detect: Zero-Day Exploitation of NetScaler Devices
IOCs (SourceIP) to detect: Zero-Day Exploitation of NetScaler Devices
IOCs (DestinationIP) to detect: Zero-Day Exploitation of NetScaler Devices
Detect Exploitation of NetScaler CVE-2026-88771 and CVE-2026-88772 Vulnerabilities [Webserver]
Simulation Execution
-
Attack Narrative & Commands: The adversary aims to exploit the NetScaler vulnerabilities (CVE-2026-88771/72) to gain Remote Code Execution (RCE). The attacker first attempts to identify the service using a known malicious User-Agent (
pitboss PPE missed too many heartbeats). They then probe for vulnerable directories like/vpn/scripts/linux/. Finally, they attempt to upload a web shell by sending a POST request containing the signature string.deb web shellwithin the body to bypass traditional file-extension filters while remaining detectable by the specific signature. -
Regression Test Script:
#!/bin/bash # Simulation script to trigger the NetScaler vulnerability detection rule TARGET="http://<TARGET_IP>" echo "[+] Starting Simulation: Triggering NetScaler CVE Detection..." # 1. Trigger via User-Agent echo "[*] Testing User-Agent trigger..." curl -s -A "pitboss PPE missed too many heartbeats" "$TARGET/" > /dev/null # 2. Trigger via Suspicious Path echo "[*] Testing Suspicious Path trigger..." curl -s -A "Mozilla/5.0" "$TARGET/vpn/scripts/linux/test.php" > /dev/null # 3. Trigger via Body Keyword echo "[*] Testing Body Keyword trigger..." curl -s -X POST -A "Mozilla/5.0" -d "payload=exploit_data_here_.deb web shell_end" "$TARGET/admin_ui/common/css/ns/ui.css" > /dev/null echo "[+] Simulation complete. Check SIEM for alerts." -
Cleanup Commands:
# No persistent files are created by this simulation as it only sends network requests. # To clean up logs, simply wait for the log retention/rotation period. echo "[+] No cleanup required: Simulation was non-persistent."