Citrix NetScaler is at the center of a new serious cyber threat, as malicious actors are actively exploiting the critical vulnerability CVE-2026-88771 to install web shells, create superuser accounts , and steal sensitive configuration data. The attack targets both NetScaler ADC and NetScaler Gateway, two of the most widely deployed network infrastructure products in enterprise environments worldwide. The scale of the attacks and the sophistication of the payloads used make this threat particularly concerning for organizations that rely on these platforms.

The vulnerability , CVE-2026-88771, has a CVSS score of 9.5. It is an improper input validation that allows an unauthenticated attacker to execute arbitrary commands on the system without any form of authentication required. This means that anyone with network access can exploit the vulnerability directly, without credentials. The vulnerability was publicly disclosed last week after the Dutch National Cyber Security Centre (NCSC-NL) sent a warning to organizations in the Netherlands, urging them to disable their devices due to active exploitation.
The LevelBlue Threat Hunt Operations & Research (THOR) team analyzed the exploit across multiple customer environments and identified malicious authentication events containing usernames controlled by the attackers. A hallmark of the attacks was the presence of the strings pitboss and NSPPE in the authentication data, which are directly related to the CVE-2026-88771 exploit. In addition, attempts were observed to use tools such as curl and wget to download additional payloads from external servers or to extract NetScaler configuration data .
See also: CVE-2026-19490: The critical vulnerability in Citrix NetScaler
Citrix NetScaler: The next stages of attack and malicious payloads
Among the most notable second-stage payloads detected in the Citrix NetScaler attacks is a Python script named main.py . This script is designed to create a reverse shell to 45.141.21[.]130 over TCP port 443 , taking advantage of encrypted HTTPS traffic to evade detection. In addition, the script looks for running processes related to /var/python/bin/customsnmpd and forcibly terminates them with the kill -9 command , ensuring exclusive control of the system.
A second payload, update_c08937.pl , is a Perl script with extensive post-exploitation capabilities. Specifically, it modifies the /flash/nsconfig/ns.conf file to create a local account named sec_monitor and assign it the superuser role . This gives the attacker permanent access to the system even if the original vulnerability is patched. At the same time, the script archives the /flash/nsconfig directory into a .tgz file and uploads it to an external server ( 64.94.85[.]67:443 ), thereby extracting sensitive NetScaler configuration data .
Of particular concern is the tactic of hiding the web shell in URLs that look like legitimate NetScaler CSS resources. The Perl script modifies /etc/httpd.conf to enable PHP execution and deploys a PHP web shell to the path /var/netscaler/logon/LogonPoint/.local_journal . This camouflage technique makes it extremely difficult for security tools and analysts to detect malicious activity. In addition, it changes the permissions of /bin/sh to 6555 , opening further backdoors into the system. After execution, the script deletes the .tgz file and itself to minimize its traces.

Citrix NetScaler CVE-2026-88772: Connection to WHIPSHOT and SLAPSHOT attacks
The disclosure of these attacks comes a day after a report by Mandiant Consulting and the Google Threat Intelligence Group (GTIG)found that dozens of organizations have been hit by attacks exploiting the companion vulnerability CVE-2026-88772. These attacks deploy PHP web shells such as WHIPSHOT and a Python tunneler codenamed SLAPSHOT. The parallel exploitation of two critical vulnerabilities in the same product suggests an organized and well-planned operation, likely by a team with significant resources and expertise.
See also: Citrix NetScaler: 6 vulnerabilities allow file read and DoS
GreyNoise has also confirmed similar activity, detecting attempts to map web shells to URLs that mimic legitimate NetScaler CSS resources . This tactic is particularly dangerous because it exploits the trust that security systems have in known URL patterns. The coordinated activity observed across multiple environments suggests that the attackers have automated scanning and exploitation tools, allowing them to target a large number of systems in a short period of time.
According to The Hacker News, LevelBlue emphasized that the observed activity goes far beyond simple vulnerability verification. The attackers are executing a full post-exploitation playbook: retrieving and executing payloads, collecting and extracting configuration data, creating privileged accounts, installing web shells, and creating reverse shells. This suggests that the goal is not just initial access, but long-term presence and control of compromised systems.

Citrix NetScaler: How to protect yourself from CVE-2026-88771
Organizations using Citrix NetScaler ADC or NetScaler Gateway should take immediate protective measures. The first and foremost step is to apply the available patches for the CVE-2026-88771 and CVE-2026-88772. If immediate remediation is not possible, it is recommended to temporarily disable the exposed devices, as suggested by NCSC-NL. In addition, it is critical to check the authentication logs for suspicious events containing the strings pitboss and NSPPE.
See also: Technical details for critical vulnerability in Citrix NetScaler
teams should also look for signs of compromise on their systems by checking for suspicious files in the /var/netscaler/logon/LogonPoint/ and /flash/nsconfig/, as well as for unauthorized accounts with superuser privileges. Monitoring outbound network traffic for connections to IP addresses 45.141.21[.]130 and 64.94.85[.]67 can reveal active compromises. In addition, it is recommended to use EDR and SIEM tools to detect suspicious activity in real time.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
