Hackers Exploit Critical Citrix NetScaler Flaw to Deploy Web Shells and Steal Configuration Data
Attackers are exploiting critical NetScaler flaw CVE-2026-88771 to plant web shells and steal appliance configurations.
LevelBlue reported active exploitation of CVE-2026-88771, a critical pre-authentication command-execution flaw in Citrix NetScaler ADC and NetScaler Gateway, scored 9.5 under CVSS 4.0. Attackers placed shell commands in usernames, fetched Python and Perl payloads for reverse shells, installed a PHP web shell, created a local superuser, and tried to archive and upload appliance configuration. Citrix confirmed zero-day exploitation and published emergency updates on September 27, 2026, with fixes in 14.1-73.37 and 13.1-64.23, including FIPS and NDcPP builds. Failed authentication does not prove injection failed, so defenders should investigate shells and data theft after patching.
- CVE-2026-88771 allows unauthenticated command execution on NetScaler ADC and Gateway.
- Citrix rates it 9.5 and issued emergency updates on September 27, 2026.
- LevelBlue observed Python and Perl payloads, web shells, and configuration theft.
- Minimum fixes listed are 14.1-73.37 and 13.1-64.23, plus FIPS and NDcPP builds.
- One payload created superuser sec_monitor and staged configuration for retrieval.
Vulnerabilities mentionedAll →
- CVE-2026-887719.51%Unauthenticated RCE in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×4
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-88771 |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| sha256 | 974b69782fdf5d67b97cfd508465939e44ee10798dbcc1e82b92d78776bad938 | bc4d7fb0b05a18570b4733aaf4f5c6f7f09be5a242c main.py SHA-256 974b69782fdf5d67b97cfd508465939e44ee10798dbcc1e82b92d78776bad938 update_c08937.pl File /var/netscaler/logon/LogonPoint/.loca |
| sha256 | e9fe43968c6c0955300e3bc4d7fb0b05a18570b4733aaf4f5c6f7f09be5a242c | RL hxxp://31.56.197[.]72:9090/lula Payload download SHA-256 e9fe43968c6c0955300e3bc4d7fb0b05a18570b4733aaf4f5c6f7f09be5a242c main.py SHA-256 974b69782fdf5d67b97cfd508465939e44ee10798db |
| url | http://23.27.143[ | st URL hxxp://62.133.62[.]80:80/xd7h/x Payload download URL hxxp://23.27.143[.]20:9000/main.py Python reverse-shell payload URL hxxp://64 |
| url | http://31.56.197[ | e_result_3567cs.tgz Configuration exfiltration endpoint URL hxxp://31.56.197[.]72:9090/lula Payload download SHA-256 e9fe43968c6c0955300e |
| url | http://62.133.62[ | ration-staging attempt IPv4 31.56.197[.]72 Payload host URL hxxp://62.133.62[.]80:80/xd7h/x Payload download URL hxxp://23.27.143[.]20:90 |
| url | http://64.94.85[ |
Full article824 words · extracted from cybersecuritynews.com · click to collapse
Hackers are exploiting CVE-2026-88771, a critical Citrix NetScaler vulnerability, to run commands, install web shells, and collect appliance configuration data.
The activity goes beyond simple testing, with malicious scripts designed to maintain access and send stolen files to attacker infrastructure. The flaw affects NetScaler ADC and NetScaler Gateway and allows command execution before authentication.
Citrix rates it 9.5 under CVSS 4.0 and says vulnerable default deployments are exposed without any extra feature enabled. Its confirmed NetScaler zero-day exploitation prompted emergency updates on September 27, 2026.
Researchers from LevelBlue’s Threat Hunt Operations & Research team identified malicious authentication events across multiple customer environments.
Their September 30 technical report describes Python and Perl payloads supporting reverse shells, privileged accounts, web shells, and attempted configuration theft. The findings do not establish that every attempt succeeded.
Hackers Exploit Critical Citrix NetScaler Flaw
Attackers placed shell commands inside usernames, often alongside pitboss, NSPPE, and unexpectedly died. Some used whoami to test execution, while others used curl or wget to fetch more code.
Commands also copied the main configuration into a web directory or archived the configuration folder for later retrieval. One variation used command substitution and ${IFS}, which represents whitespace without literal spaces.
.webp)
This gives defenders another useful search pattern: suspicious authentication fields containing crash-related text together with commands for downloading, reading, or archiving files.
The Python payload overwrites an appliance component with reverse-shell code. That code connects outward over TCP port 443, redirects input and output to the connection, and starts an interactive shell. The original script also terminates matching processes associated with the targeted component.
Web Shells and Configuration Theft
The Perl payload creates a local superuser account, archives the configuration directory, and attempts to upload the archive. It then removes the archive and deletes itself. Missing files therefore do not prove that the payload failed or that no data left the appliance.
It also changes shell permissions to 6555 and installs a PHP web shell. Changes to the HTTP server configuration enable PHP and expose the shell through addresses resembling normal CSS resources.
This echoes Google’s NetScaler web-shell findings involving disguised files, although LevelBlue does not identify its payload as the same malware.
The installed shell supports remote commands, uploads, and downloads. Together with the added administrator account, these changes give attackers several ways to keep control of the appliance after initial exploitation.
Security teams should examine authentication records, unexpected configuration access, new web-directory files, privileged account changes, and outbound traffic following suspicious login events.
.webp)
LevelBlue warns that failed authentication does not mean command injection failed; investigators must check what happened afterward.
Known hashes and IP addresses help locate this activity, but attackers can change them. More lasting warning signs include shell commands in authentication data, altered appliance components, and configuration archives placed where the web server can serve them.
Carefully review network records together with file and account changes to determine whether an attempt led to a working shell or a transfer of configuration data. Administrators should follow Citrix’s official security bulletin and install an appropriate supported update.
The earlier urgent NetScaler patch guidance also stresses investigating possible compromise, rather than treating an update as proof that an appliance is clean.
The bulletin lists fixes for this flaw in 14.1-73.37 and 13.1-64.23, with corresponding FIPS and NDcPP builds. These are the minimum fixes in that advisory, not a claim that they are the latest releases. Teams should check current vendor guidance before choosing an update, especially where other NetScaler vulnerabilities also apply.
Indicators of compromise (IoCs):-
| Type | Indicator | Observed role |
|---|---|---|
| IPv4 | 70.172.58[.]168 | Exploitation source |
| IPv4 | 45.141.21[.]130 | Reverse-shell C2 |
| IPv4 | 162.243.36[.]88 | Exploitation source |
| IPv4 | 173.40.135[.]209 | Exploitation source |
| IPv4 | 47.230.224[.]154 | Exploitation source |
| IPv4 | 23.27.143[.]20 | Exploit source; payload host |
| IPv4 | 62.133.62[.]80 | Payload host |
| IPv4 | 64.94.85[.]67 | Exploit, payload, exfiltration infrastructure |
| IPv4 | 92.118.204[.]229 | Command-execution testing |
| IPv4 | 87.224.84[.]82 | Configuration-staging attempt |
| IPv4 | 31.56.197[.]72 | Payload host |
| URL | hxxp://62.133.62[.]80:80/xd7h/x | Payload download |
| URL | hxxp://23.27.143[.]20:9000/main.py | Python reverse-shell payload |
| URL | hxxp://64.94.85[.]67:443/update_c08937.pl | Perl payload |
| URL | hxxp://64.94.85[.]67:443/update_result_3567cs.tgz | Configuration exfiltration endpoint |
| URL | hxxp://31.56.197[.]72:9090/lula | Payload download |
| SHA-256 | e9fe43968c6c0955300e3bc4d7fb0b05a18570b4733aaf4f5c6f7f09be5a242c | main.py |
| SHA-256 | 974b69782fdf5d67b97cfd508465939e44ee10798dbcc1e82b92d78776bad938 | update_c08937.pl |
| File | /var/netscaler/logon/LogonPoint/.local_journal | PHP web shell |
| File | /tmp/update_result_3567cs.tgz | Staged configuration archive |
| File | /var/netscaler/logon/insight-new.js | Staged configuration |
| File | /var/netscaler/logon/LogonPoint/xua.html | Staged configuration archive |
| Account | sec_monitor | Created superuser account |
| Component | /var/python/bin/customsnmpd | Reverse-shell overwrite target |
| Configuration | /flash/nsconfig/ns.conf | Modified account configuration |
| Directory | /flash/nsconfig | Archived configuration data |
| Configuration | /etc/httpd.conf | PHP and alias changes |
| Permissions | /bin/sh: 6555 | Altered shell permissions |
| Alias | LogonUISimple.html.style.min.css | Disguised web-shell resource |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.