NetScaler ADC and NetScaler Gateway
CVE-2026-88771: Unauthenticated command injection in NetScaler ADC and Gateway
An unauthenticated attacker can run commands as root on NetScaler ADC and Gateway in the default configuration. Exploited as a zero-day since at least September 20, 2026, then in mass attacks after a public proof of concept.
Published Updated
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| NetScaler ADC and Gateway 14.1 | 14.1-73.37 or later |
| NetScaler ADC and Gateway 13.1 | 13.1-64.23 or later |
| NetScaler ADC 14.1 FIPS | 14.1-73.37 FIPS or later |
| NetScaler ADC 13.1 FIPS and NDcPP | 13.1.37.279 or later |
| Citrix-managed cloud services and Adaptive Authentication | Upgraded by Cloud Software Group |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
A pre-authentication command injection in NetScaler ADC and Gateway. An unauthenticated attacker can run commands as root on the appliance. Citrix rates it 9.5 (CVSS 4.0) and confirms exploitation of unmitigated appliances.
watchTowr traced the root cause. A NetScaler script, ns_monuploadd_err.pl, reads a crashed-process filename out of the logs and pastes it into a second shell command without checking it. An attacker who gets crafted text into the logs, for example through the username field of a failed login, gets that text run as a command the next time the script runs. That can take up to 24 hours.
It was a zero-day. Rapid7 saw the first attempt on September 20, a week before Citrix published a fix. After watchTowr published its analysis on September 28, exploitation turned into mass scanning, and eSentire saw attackers reusing watchTowr’s payload within hours. Public reporting also describes web shells, stolen configuration files, backdoor admin accounts and reverse shells.
The same bulletin fixes CVE-2026-88772, a separate DTLS memory overflow that was also exploited as a zero-day. A third bug, CVE-2026-88779, was exploited and fixed on October 4. Patch to the builds for that CVE.
Am I affected?
You’re affected if you run a customer-managed NetScaler ADC or Gateway below these builds:
- 14.1 before 14.1-73.37
- 13.1 before 13.1-64.23
- 14.1 FIPS before 14.1-73.37 FIPS
- 13.1 FIPS and NDcPP before 13.1.37.279
Rapid7 and watchTowr say the default configuration is vulnerable. No optional feature has to be enabled. Any NetScaler that logs attacker-supplied HTTP data may be reachable, so don’t assume only your login page matters.
BleepingComputer reports that Secure Private Access Hybrid deployments using NetScaler instances are also in scope. Cloud Software Group is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication itself.
Citrix’s bulletin CTX697096 has a section on determining whether an appliance meets the preconditions, according to Unit 42. Use it to confirm exposure.
What to do
- Upgrade now, outside your normal change window. Move to at least the builds above. Rapid7 lists newer builds that also fix CVE-2026-88779: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1.37.282. Prefer those.
- Don’t wait for a workaround. Rapid7 and Unit 42 list none, and BleepingComputer’s coverage of the bulletin describes none. If you can’t patch yet, cut internet exposure where you can. Some IT suppliers advised shutting appliances down.
- Assume compromise if you were exposed and unpatched. Patching does not remove an attacker who is already on the box (Sophos, Unit 42). Citrix’s own detection script may miss real compromises.
- Preserve evidence before you reboot or rebuild. Unit 42 asks for a VPX snapshot, logs from your syslog server and NetScaler Console, a technical support bundle and a packet engine core dump. Citrix article CTX694799 covers what to do when you suspect compromise.
- Rebuild any confirmed or likely compromised appliance and rotate secrets. Rapid7 notes the stolen archive holds
ns.conf(admin password hashes and LDAP, RADIUS and TACACS bind passwords), TLS certificates and private keys, SSH host keys and license files. Rotate all of them, and revoke and reissue certificates.
Detection
Look back to at least September 20, 2026. Unit 42 and Lupovis saw earlier probing, but the first injection attempt reported by Rapid7 is that date.
Logs
- Search NetScaler logs for the string
pitboss. The injected text is framed aspitboss PPE unexpectedly died NSPPEfollowed by a command (Unit 42, eSentire). This also shows attempts against patched devices, so it doesn’t prove success. - Rapid7 saw the command in a rejected-login log entry. Shell metacharacters or
${IFS}in a username field are a red flag. - Look for POSTs to
/nf/auth/doAuthentication.dowhose body containspitboss PPE unexpectedly died NSPPE(Lupovis). - Look for a base64-encoded dropper in the User-Agent header in
/var/log/httpaccess-vpn.log(Unit 42). - Look for requests to
/vpn/c, which serves the stolen config archive without authentication (Rapid7). - Look for requests to
.ctxs.receiver, to CSS-looking aliases such as/logon/LogonPoint/custom/receiver.min.cssand/logon/LogonPoint/css/LogonUISimple.html.style.min.css, and to the.debfiles under/vpn/scripts/linux/(Unit 42, eSentire). - Look for requests carrying the header
HTTP_NSC_CLIENTTYPE(eSentire).
On the appliance
- Unexpected files in
/var/netscaler/logon/LogonPoint/and/var/netscaler/gui/vpn/scripts/linux/. - Edits to
/etc/httpd.conf, especiallyphp_flag engine onand new Alias entries. - The SUID and SGID bits set on
/bin/sh, which Unit 42 and eSentire both saw. - New superuser accounts in
/flash/nsconfig/ns.conf, such asgw_health(watchTowr), and unfamiliarauthorized_keysentries. - Outbound connections or DNS lookups to the indicators listed above, and a service listening on tcp/37512 (watchTowr’s trojanized Dropbear SSH).
Other published indicators
Arctic Wolf and Mandiant published indicators for the follow-on and earlier attacks, and CERT-EU published hunting advice. We could not open those pages, so they aren’t included here. Check them directly.
Indicators of compromise
Many addresses are rented servers or Cloudflare WARP ranges. Use them to search past logs, not as a block list. Post-disclosure scanning may not match the pre-disclosure indicators. Citrix warned that its own detection script may miss real compromises.
The .txt list has one IP per line and a fixed address, so a firewall can pull it as an External Dynamic List: https://patchtonight.com/iocs/CVE-2026-88771.txt
| Indicator | Type | Reported by |
|---|---|---|
| 149.104.78[.]208 | IPSource of the earliest observed injection attempt, September 20 | Rapid7 |
| 77.83.199[.]39 | IPSeptember 21 injection chain | Unit 42 |
| 78.47.24[.]217 | IPSeptember 21 injection chain | Unit 42 |
| 139.180.152[.]138 | IPSeptember 21 injection chain | Unit 42 |
| 193.149.176[.]207 | IPMost of the .deb download requests | Unit 42 |
| 162.33.178[.]9 | IP | Unit 42 |
| 216.245.184[.]164 | IP | Unit 42 |
| 138.199.200[.]90 | IPHetzner server used for exfiltration | Lupovis, via Help Net Security |
| 64.94.85[.]67 | IPHosts the Perl installer update_c08937.pl | eSentire |
| 62.133.62[.]80 | IPPlatypus stager host | eSentire |
| 23.27.143[.]20 | IPPython script host | eSentire |
| 45.141.21[.]130 | IPReverse shell C2 | eSentire |
| entretiensol[.]com | DomainPlatypus C2 on port 443 | eSentire |
| instances.httpworkbench[.]com | DomainOutbound DNS lookups for names ending in this suffix | Lupovis, via Help Net Security |
| /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver | File pathPHP web shell | Rapid7, Unit 42 |
| /var/netscaler/logon/LogonPoint/.local_journal | File pathPHP web shell | eSentire, watchTowr |
| /var/netscaler/gui/vpn/c | File pathGzipped copy of /flash/nsconfig, downloadable without authentication at /vpn/c | Rapid7 |
| /var/netscaler/gui/vpn/scripts/linux/nsgtrust.deb | File pathPHP web shell disguised as a .deb file | eSentire |
| /var/netscaler/.ns_suidcmd | File path | Unit 42 |
| /var/vpn/ns_helper | File pathStaged Sliver implant | watchTowr |
| /var/python/bin/customsnmpd | File pathReverse shell disguised as an SNMP daemon | eSentire |
| ed082f744f035035900f67edf438f2f7d0528ac501234f63d476d65273cdb9a1 | SHA-256SHA-256 of the .ctxs.receiver web shell | Rapid7 |
| ae22ef2517b5c0fb47f78745b9cb5260acee0e751b89bcd354640ff8bc8d29ec | SHA-256SHA-256 of nsg64.deb | Unit 42 |
| 7add390ceee4a1373211b3e340451b34f08965fc4d805f94c9b8cebdc0775774 | SHA-256SHA-256 of nsgtrust.deb | eSentire |
| Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.9565.730 Safari/537.36 | User agentSliver implant beacons | watchTowr |
| wfr | Account nameAccount name in the logged FAILED_BAD_LOGIN event carrying the injection | Rapid7 |
| gw_health | Account nameSuperuser account written to ns.conf | watchTowr |
watchTowr keeps a fuller indicator list in its IOC repository.
Sources
- Citrix advisory CTX697096
- CVE record (Citrix CNA)
- CISA Known Exploited Vulnerabilities catalog
- Rapid7, zero-day exploitation of NetScaler
- Unit 42 threat brief
- watchTowr Labs root-cause analysis
- watchTowr post-exploitation analysis and artifacts
- eSentire, exploitation clusters
- Help Net Security, mass attacks
- BleepingComputer, Citrix bulletin coverage
- Sophos
Page changelog
- Full analysis published.
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.