Critical Citrix NetScaler CVE-2026-88771 Exploited for Reverse Shells and Persistent Access
Attackers are exploiting critical Citrix NetScaler CVE-2026-88771 for reverse shells and persistent privileged access.
LevelBlue reports attackers exploiting CVE-2026-88771, a critical pre-authentication command-injection flaw (CVSS 9.5) in Citrix NetScaler ADC and NetScaler Gateway, across multiple customer environments. Observed activity includes reverse shells, retrieval of Perl and Python payloads, creation of privileged account sec_monitor, theft of ns.conf, and a PHP web shell under LogonPoint. Citrix issued fixes on September 27; LevelBlue lists patched builds 14.1-73.37 and 13.1-64.23, plus corresponding FIPS builds. Investigators should hunt authentication anomalies, altered customsnmpd, .local_journal, and outbound callbacks, noting payloads may delete their own artifacts.
- CVE-2026-88771 is pre-auth command injection in NetScaler ADC and Gateway, CVSS 9.5.
- LevelBlue saw exploitation in multiple customer environments beyond mere scanning.
- Payloads fetch secondary scripts, open a reverse shell, and create superuser sec_monitor.
- A PHP web shell is installed and ns.conf is staged under web-accessible paths.
- Fixed builds are 14.1-73.37 and 13.1-64.23; Citrix patched on September 27.
Vulnerabilities mentionedAll →
- CVE-2026-887719.51%Unauthenticated RCE in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×4
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-88771 |
Full article695 words · extracted from gbhackers.com · click to collapse
Attackers are exploiting CVE-2026-88771, a critical pre-authentication command-injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway, to deploy reverse shells, create privileged accounts, and establish persistent access.
LevelBlue’s Threat Hunt Operations & Research (THOR) team identified malicious authentication events across multiple customer environments, documenting activity extending beyond vulnerability testing into payload execution and configuration theft attempts.
LevelBlue’s September 30 investigation links attacker-controlled usernames to commands that retrieve malware, stage sensitive appliance configuration, and modify legitimate components.
Its earlier advisory assigns the vulnerability a CVSS score of 9.5 and reports that Citrix released patches on September 27.
Observed authentication data repeatedly contained pitboss, NSPPE, and “unexpectedly died” alongside injected shell commands.
Some attempts invoked whoami to validate execution; others used curl or wget to retrieve secondary payloads, including update_c08937.pl and a resource named lula.
Attackers also targeted /flash/nsconfig/ns.conf, copying its contents into /var/netscaler/logon/insight-new.js.
Separate commands archived the entire /flash/nsconfig directory into /var/netscaler/logon/LogonPoint/xua.html, placing configuration data beneath a web-accessible directory.
Several commands substituted ${IFS} for literal spaces, while another used backtick command substitution instead of semicolon-delimited injection.
These variations give investigators additional search patterns without requiring an exact match against one exploit string.
One second-stage Python payload, main.py, was hosted at 23.27.143[.]20:9000.
It overwrites /var/python/bin/customsnmpd with code that connects to 45.141.21[.]130:443, redirects standard input, output, and error to the socket, and launches an interactive /bin/sh.

The initial script also identifies and terminates processes associated with customsnmpd.
A separate Perl payload, update_c08937.pl, was retrieved from 64.94.85[.]67:443 and piped directly into Perl.
This execution pattern avoids first saving the downloaded script to a fixed filesystem location.
LevelBlue Researchers identified malicious NetScaler authentication, events containing attacker-controlled usernames designed to exploit CVE-2026-88771.
Citrix NetScaler CVE-2026-88771 Exploited
The Perl code modifies /flash/nsconfig/ns.conf to create sec_monitor with superuser privileges.

It archives the configuration directory into /tmp/update_result_3567cs.tgz and attempts to upload that archive to the same infrastructure. Afterwards, it removes the archive and deletes itself, limiting residual evidence.
The payload additionally changes /bin/sh permissions to 6555 and installs a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal.
Changes to /etc/httpd.conf enable PHP execution and expose the implant through CSS-like URLs, including LogonUISimple.html.style.min.css and randomized hexadecimal variants.
The shell supports remote command execution, uploads, and downloads.
Defenders should correlate suspicious authentication fields with outbound connections, configuration access, and appliance modifications.
Particularly valuable artifacts include sec_monitor, altered customsnmpd content, .local_journal, unexpected HTTP Alias or SetHandler directives, and changes to shell permissions.
Missing payloads or archives do not establish that exploitation failed: the Perl script explicitly removes artifacts.
Conversely, an injected authentication event alone does not demonstrate successful compromise; subsequent filesystem, process, and network evidence remains essential.
The findings distinguish attempted exploitation from verified downstream activity. THOR’s report describes commands observed in authentication telemetry and capabilities identified through payload analysis, rather than attributing every capability to every targeted appliance.
That distinction matters when assessing incident scope: configuration staging, an outbound callback, and a newly privileged account represent different investigative milestones and should be validated independently against available logs and preserved appliance evidence during triage.
LevelBlue lists fixed standard builds as 14.1-73.37 and 13.1-64.23, with FIPS fixes at 14.1-73.37 FIPS and 13.1-37.279 for FIPS/NDcPP.
Organizations should apply appropriate updates promptly, review local accounts, reset active-account authentication, and collect surrounding network telemetry.
The published indicators are investigative pivots, not an exhaustive inventory; behavioral hunting remains necessary as infrastructure and filenames change.
Indicators of Compromise
| Indicator | Type | Description |
| 70.172.58[.]168 | IPv4 | Source of NetScaler exploitation attempts |
| 45.141.21[.]130 | IPv4 | Reverse-shell C2 infrastructure |
| 162.243.36[.]88 | IPv4 | Source of NetScaler exploitation attempts |
| 173.40.135[.]209 | IPv4 | Source of NetScaler exploitation attempts |
| 47.230.224[.]154 | IPv4 | Source of NetScaler exploitation attempts |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.