Security advisories

Update – Ongoing Exploitation of Citrix NetScaler ADC and NetScaler Gateway Vulnerabilities (CVE-2026-88771 & CVE-2026-88772)

September 29, 2026

7 MINS READ

THE THREAT

As of September 29th, 2026, eSentire has observed in-the-wild exploitation of CVE-2026-88771 and CVE-2026-88772, with identified attacks being traced back to early-September. CVE-2026-88771 (CVSS: 9.8) and CVE-2026-88772 (CVSS: 8.1) are critical vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway that can lead to unauthenticated Remote Code Execution (RCE). eSentire published an initial advisory for these vulnerabilities on September 28th. Both vulnerabilities were disclosed by Citrix on September 27th, who confirmed that exploitation had been previously identified. Reporting from CERT-EU and Google also highlight observed attacks, resulting in the deployment of webshells.

As exploitation is ongoing, organizations should ensure that relevant patches are applied immediately. Any internet-facing NetScaler appliance that was unpatched in early September 2026 should be treated as compromised until an integrity assessment confirms they were not affected.

What we're doing about it

What you should do about it

Additional information

In September 2026, eSentire's Threat Response Unit (TRU) observed a threat actor exploiting CVE-2026-88771 against Internet-facing Citrix NetScaler Gateway appliances as early as September 5th, more than three weeks before the vulnerability was publicly disclosed. In one instance, the actor employed a two-stage technique that abuses the appliance's own logging. The actor sent a rapid series of web requests for a fictitious icon file (/vpn/media/<name>.ico), each with base64-encoded PHP code appended to the User-Agent string, causing the appliance's web server to record the code in its access log. At the same time, the actor submitted crafted values in the Gateway login username field that imitates a NetScaler Packet Engine heartbeat message, followed by operating system commands. A built-in log-processing script passes these commands to a shell, directing the appliance to extract the staged code from its logs, decode it and execute it with PHP. Exploitation does not depend on the login succeeding.

The decoded payload is a PHP webshell designed for stealth and persistence. TRU has identified at least two variants of this webshell. The first, referred to here as the .ico variant, is publicly available on VirusTotal. The second, referred to here as the .deb variant, has not been observed by TRU in public malware repositories. It contains the same command-handling code as the .ico variant but executes through files with a .deb extension, allowing it to blend in with the legitimate VPN client installation packages stored in the same directory. When first executed, each variant:

Once active, the webshell executes base64-encoded PHP code supplied in the NSC_CLIENTTYPE HTTP request header, a name chosen to resemble legitimate NetScaler traffic. It always returns an HTTP 404 "Not Found" response, so attacker traffic appears to be routine requests for missing files. In the .ico variant intrusion examined by TRU, the actor staged the payload and then polled the webshell path hourly, and later every ten minutes, for nearly two days. The webshell installation does not appear to have been completed in that intrusion. In a separate intrusion involving the .deb variant, TRU confirmed that the webshell was installed and actively operated from September 5th, with webshell responses indicative of data exfiltration. The actor subsequently used access obtained through the compromised Gateway to open sessions on internal virtual desktops and connect back to the NetScaler appliance over SSH, confirming lateral movement into the internal network. The same technique and payload were also associated with webshell deployment and data theft at other organizations during the same period.

The observed attacks closely match findings by CERT-EU, who highlight attacks leveraging HTTP requests with base64-encoded user agents, which were executed to deploy webshells following exploitation of CVE-2026-88771. Google highlighted attacks targeting CVE-2026-88772, which resulted in the deployment of the WHIPSHOT webshell and SLAPSHOT TCP tunneling tool. No attribution for the attacks were provided by CERT-EU or Google within their reports, but security researcher Kevin Beaumont suggests that the attacks may have been espionage-motivated. Following the disclosure of both flaws, various technical reports and unverified Proof-of-Concept (PoC) exploit code have been published, opening the door for threat actors of all skill levels and motivations to operationalize the exploits within attacks.

Organizations that operated Internet-facing, unpatched NetScaler appliances in early September 2026 should treat those appliances as potentially compromised until an integrity assessment demonstrates otherwise.

Fixed Versions:

Indicators of Compromise
34[.]90[.]151[.]231 Reconnaissance + webshell delivery
31[.]56[.]197[.]72 Payload host
64[.]94[.]85[.]67 Payload host
23[.]27[.]143[.]20 Payload host
144[.]172[.]108[.]78 Exploitation source
62[.]133[.]62[.]80 Payload host
149[.]104[.]78[.]141 Exploitation source
185[.]156[.]46[.]162 Exploitation source
77[.]83[.]199[.]39 Webshell delivery
139[.]180[.]152[.]138 Webshell delivery
185[.]243[.]41[.]247 Campaign infrastructure
82[.]167[.]14[.]7 Exploitation source
153[.]75[.]82[.]220 Exploitation source
216[.]203[.]21[.]233 Exploitation source
5ea5ea61e9062822bee3f66ef5ff47c217178d9e31936ad6daf10c5dfae44d12 SHA256 hash of webshell (.ico variant)
7add390ceee4a1373211b3e340451b34f08965fc4d805f94c9b8cebdc0775774 SHA256 hash of webshell (.deb variant)

Webshell Indicators:

References:

[1] https://nvd.nist.gov/vuln/detail/cve-2026-88771
[2] https://nvd.nist.gov/vuln/detail/cve-2026-88772
[3] https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
[4] https://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771
[5] https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances
[6] https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/
[7] https://cyberplace.social/@GossiTheDog/117351107654208046

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories