NetScaler ADC and NetScaler Gateway

CVE-2026-88771: Unauthenticated command injection in NetScaler ADC and Gateway

An unauthenticated attacker can run commands as root on NetScaler ADC and Gateway in the default configuration. Exploited as a zero-day since at least September 20, 2026, then in mass attacks after a public proof of concept.

Published Updated

ExploitedYes, in CISA KEVAdded 27 Sept 2026
Ransomware useNot reportedPer CISA
SeverityCRITICALCVSS 4.0 9.5
EPSS1.1%Chance of exploitation in 30 days
Public exploitYes
FixAvailable

Affected and fixed versions

Product / branchFixed in
NetScaler ADC and Gateway 14.114.1-73.37 or later
NetScaler ADC and Gateway 13.113.1-64.23 or later
NetScaler ADC 14.1 FIPS14.1-73.37 FIPS or later
NetScaler ADC 13.1 FIPS and NDcPP13.1.37.279 or later
Citrix-managed cloud services and Adaptive AuthenticationUpgraded by Cloud Software Group

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

A pre-authentication command injection in NetScaler ADC and Gateway. An unauthenticated attacker can run commands as root on the appliance. Citrix rates it 9.5 (CVSS 4.0) and confirms exploitation of unmitigated appliances.

watchTowr traced the root cause. A NetScaler script, ns_monuploadd_err.pl, reads a crashed-process filename out of the logs and pastes it into a second shell command without checking it. An attacker who gets crafted text into the logs, for example through the username field of a failed login, gets that text run as a command the next time the script runs. That can take up to 24 hours.

It was a zero-day. Rapid7 saw the first attempt on September 20, a week before Citrix published a fix. After watchTowr published its analysis on September 28, exploitation turned into mass scanning, and eSentire saw attackers reusing watchTowr’s payload within hours. Public reporting also describes web shells, stolen configuration files, backdoor admin accounts and reverse shells.

The same bulletin fixes CVE-2026-88772, a separate DTLS memory overflow that was also exploited as a zero-day. A third bug, CVE-2026-88779, was exploited and fixed on October 4. Patch to the builds for that CVE.

Am I affected?

You’re affected if you run a customer-managed NetScaler ADC or Gateway below these builds:

  • 14.1 before 14.1-73.37
  • 13.1 before 13.1-64.23
  • 14.1 FIPS before 14.1-73.37 FIPS
  • 13.1 FIPS and NDcPP before 13.1.37.279

Rapid7 and watchTowr say the default configuration is vulnerable. No optional feature has to be enabled. Any NetScaler that logs attacker-supplied HTTP data may be reachable, so don’t assume only your login page matters.

BleepingComputer reports that Secure Private Access Hybrid deployments using NetScaler instances are also in scope. Cloud Software Group is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication itself.

Citrix’s bulletin CTX697096 has a section on determining whether an appliance meets the preconditions, according to Unit 42. Use it to confirm exposure.

What to do

  1. Upgrade now, outside your normal change window. Move to at least the builds above. Rapid7 lists newer builds that also fix CVE-2026-88779: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1.37.282. Prefer those.
  2. Don’t wait for a workaround. Rapid7 and Unit 42 list none, and BleepingComputer’s coverage of the bulletin describes none. If you can’t patch yet, cut internet exposure where you can. Some IT suppliers advised shutting appliances down.
  3. Assume compromise if you were exposed and unpatched. Patching does not remove an attacker who is already on the box (Sophos, Unit 42). Citrix’s own detection script may miss real compromises.
  4. Preserve evidence before you reboot or rebuild. Unit 42 asks for a VPX snapshot, logs from your syslog server and NetScaler Console, a technical support bundle and a packet engine core dump. Citrix article CTX694799 covers what to do when you suspect compromise.
  5. Rebuild any confirmed or likely compromised appliance and rotate secrets. Rapid7 notes the stolen archive holds ns.conf (admin password hashes and LDAP, RADIUS and TACACS bind passwords), TLS certificates and private keys, SSH host keys and license files. Rotate all of them, and revoke and reissue certificates.

Detection

Look back to at least September 20, 2026. Unit 42 and Lupovis saw earlier probing, but the first injection attempt reported by Rapid7 is that date.

Logs

  • Search NetScaler logs for the string pitboss. The injected text is framed as pitboss PPE unexpectedly died NSPPE followed by a command (Unit 42, eSentire). This also shows attempts against patched devices, so it doesn’t prove success.
  • Rapid7 saw the command in a rejected-login log entry. Shell metacharacters or ${IFS} in a username field are a red flag.
  • Look for POSTs to /nf/auth/doAuthentication.do whose body contains pitboss PPE unexpectedly died NSPPE (Lupovis).
  • Look for a base64-encoded dropper in the User-Agent header in /var/log/httpaccess-vpn.log (Unit 42).
  • Look for requests to /vpn/c, which serves the stolen config archive without authentication (Rapid7).
  • Look for requests to .ctxs.receiver, to CSS-looking aliases such as /logon/LogonPoint/custom/receiver.min.css and /logon/LogonPoint/css/LogonUISimple.html.style.min.css, and to the .deb files under /vpn/scripts/linux/ (Unit 42, eSentire).
  • Look for requests carrying the header HTTP_NSC_CLIENTTYPE (eSentire).

On the appliance

  • Unexpected files in /var/netscaler/logon/LogonPoint/ and /var/netscaler/gui/vpn/scripts/linux/.
  • Edits to /etc/httpd.conf, especially php_flag engine on and new Alias entries.
  • The SUID and SGID bits set on /bin/sh, which Unit 42 and eSentire both saw.
  • New superuser accounts in /flash/nsconfig/ns.conf, such as gw_health (watchTowr), and unfamiliar authorized_keys entries.
  • Outbound connections or DNS lookups to the indicators listed above, and a service listening on tcp/37512 (watchTowr’s trojanized Dropbear SSH).

Other published indicators

Arctic Wolf and Mandiant published indicators for the follow-on and earlier attacks, and CERT-EU published hunting advice. We could not open those pages, so they aren’t included here. Check them directly.

Indicators of compromise

Many addresses are rented servers or Cloudflare WARP ranges. Use them to search past logs, not as a block list. Post-disclosure scanning may not match the pre-disclosure indicators. Citrix warned that its own detection script may miss real compromises.

The .txt list has one IP per line and a fixed address, so a firewall can pull it as an External Dynamic List: https://patchtonight.com/iocs/CVE-2026-88771.txt

IndicatorTypeReported by
149.104.78[.]208IPSource of the earliest observed injection attempt, September 20Rapid7
77.83.199[.]39IPSeptember 21 injection chainUnit 42
78.47.24[.]217IPSeptember 21 injection chainUnit 42
139.180.152[.]138IPSeptember 21 injection chainUnit 42
193.149.176[.]207IPMost of the .deb download requestsUnit 42
162.33.178[.]9IPUnit 42
216.245.184[.]164IPUnit 42
138.199.200[.]90IPHetzner server used for exfiltrationLupovis, via Help Net Security
64.94.85[.]67IPHosts the Perl installer update_c08937.pleSentire
62.133.62[.]80IPPlatypus stager hosteSentire
23.27.143[.]20IPPython script hosteSentire
45.141.21[.]130IPReverse shell C2eSentire
entretiensol[.]comDomainPlatypus C2 on port 443eSentire
instances.httpworkbench[.]comDomainOutbound DNS lookups for names ending in this suffixLupovis, via Help Net Security
/var/netscaler/logon/LogonPoint/custom/.ctxs.receiverFile pathPHP web shellRapid7, Unit 42
/var/netscaler/logon/LogonPoint/.local_journalFile pathPHP web shelleSentire, watchTowr
/var/netscaler/gui/vpn/cFile pathGzipped copy of /flash/nsconfig, downloadable without authentication at /vpn/cRapid7
/var/netscaler/gui/vpn/scripts/linux/nsgtrust.debFile pathPHP web shell disguised as a .deb fileeSentire
/var/netscaler/.ns_suidcmdFile pathUnit 42
/var/vpn/ns_helperFile pathStaged Sliver implantwatchTowr
/var/python/bin/customsnmpdFile pathReverse shell disguised as an SNMP daemoneSentire
ed082f744f035035900f67edf438f2f7d0528ac501234f63d476d65273cdb9a1SHA-256SHA-256 of the .ctxs.receiver web shellRapid7
ae22ef2517b5c0fb47f78745b9cb5260acee0e751b89bcd354640ff8bc8d29ecSHA-256SHA-256 of nsg64.debUnit 42
7add390ceee4a1373211b3e340451b34f08965fc4d805f94c9b8cebdc0775774SHA-256SHA-256 of nsgtrust.debeSentire
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.9565.730 Safari/537.36User agentSliver implant beaconswatchTowr
wfrAccount nameAccount name in the logged FAILED_BAD_LOGIN event carrying the injectionRapid7
gw_healthAccount nameSuperuser account written to ns.confwatchTowr

watchTowr keeps a fuller indicator list in its IOC repository.

Sources

Page changelog

  • Full analysis published.

KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.