Historical snapshot as of . Check official advisories for current status. Not a live feed.
Critical Citrix NetScaler ADC / NetScaler Gateway
PitScaler - Citrix NetScaler Zero-Day Crisis
Two NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, were exploited in the wild before disclosure. Both are rated CVSS 4.0 9.5 Critical. Citrix fixed them in bulletin CTX697096 together with six other CVEs. [Citrix CTX697096][CISA]
Confirmed exploited zero-days
2
CVE-2026-88771, CVE-2026-88772
CVEs in bulletin CTX697096
8
CVE-2026-88771 to -88778
Public disclosure
15:51 UTC, per GreyNoise
CISA KEV federal deadline
A deadline that was still ahead at snapshot time
Official Citrix bulletin and government advisories
Research third-party technical analysis
Telemetry sensor data (GreyNoise)
Reported Beaumont's posts, community and press reports. These are claims and have not been independently verified.
Overview
What happened
Citrix published bulletin CTX697096 with fixes for eight NetScaler ADC and Gateway CVEs on 27 September 2026. [Citrix] The same day, CISA added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities catalog, with a federal remediation deadline of 30 September. [CISA]
Google GTIG and Mandiant report that CVE-2026-88772 has been exploited since at least early September. Organisations in North America and Europe in government, financial services, education, and legal and professional services were likely affected. The attackers used new custom malware: WHIPSHOT, a PHP webshell, and SLAPSHOT, a Python tunneler that reaches into internal networks. [GTIG/Mandiant]
Unit 42 counted 50,277 exposed NetScaler instances that could potentially be vulnerable, as of 27 September, from its Cortex Xpanse data. That is an exposure count, not a count of compromised systems. [Unit 42]
GreyNoise sensors recorded exploitation from one IP on 24 September, three days before public disclosure. GreyNoise's retro-hunt found no other exploitation sessions before disclosure. That result covers GreyNoise's own sensors, not all internet activity. [GreyNoise][GreyNoise Chronicle]
The name
Kevin Beaumont (@GossiTheDog) coined the name "PitScaler" on 28 September. [Beaumont] It refers to the root cause: a Perl script writing to /tmp. CERT-EU's writeup title describes this as Citrix taking execute logging a bit too literally. [CERT-EU]
Reported by Beaumont Unverified claims
Chaining CVE-2026-88771, -88772 and -88773 gives unauthenticated RCE in the default appliance configuration. Webshells were dropped throughout September. He calls the attackers Probably nation state aligned. [post]
He says he is tracking over 100 victim organisations, each with a unique webshell. [post]
His firmware version scanning suggests fewer than 10% of boxes are patched. [post]
These figures are Beaumont's own public statements and have not been independently confirmed.
The eight CVEs in CTX697096
Citrix's bulletin lists all eight CVEs. Only CVE-2026-88771 and CVE-2026-88772 are confirmed exploited. [Citrix][CISA]
Timeline
Times are UTC unless marked otherwise. Events without a time show only their date. Expand an event to see its sources.
GreyNoise published its set on 28 September, marked TLP:CLEAR. GreyNoise has announced a longer "GreyNoise Labs" version, but the link on its blog was still a placeholder at snapshot time.
IFIN says the observables it shares were shared without restriction.
Truesec's page is public and has no TLP marking.
GTIG/Mandiant's blog is public and has no TLP marking. GTIG keeps its full IOC collection for registered GTI users only.
How to read these. Each indicator was observed by the source named in its row. None of them is a universal indicator for every victim. Beaumont reports that webshell names and attacker IPs are unique per victim. [Beaumont][Beaumont] An empty search result proves nothing.
Publicly released indicators for NetScaler CVE-2026-88771 and CVE-2026-88772 exploitation
Type
Exact value
Source
Context
Caveat
Sharing
Post-exploitation behaviour observed by GreyNoise
Set setuid and setgid on /bin/sh.
Planted a PHP webshell that authenticates by cookie.
Killed and restarted httpd, for anti-forensics or to activate the changed config.
A Reddit user described one sample of the .ctxs.receiver file, and IFIN relayed the description. This is unconfirmed. [IFIN]
The file is a 237-byte PHP one-liner.
It runs a URL-decoded cookie value through passthru(), but only when a second cookie matches a hardcoded 16-character hex token.
NetScaler uses both cookie names legitimately, so the traffic blends in.
The file survived a reboot and the upgrade to 14.1-73.37.
The token likely differs per victim, so search the file's content rather than relying on its hash.
Available only through support or under NDA. [post]
Incomplete: it does not check for suid on /bin/sh. [post]
Misses earlier semi-successful attempts once logs have rotated. [post]
Beaumont also says Some really big orgs are backdoored after patching still. He has asked national CSIRTs (NCSCs) to publish a detection script. [post]
GTIG/Mandiant artefacts and YARA Passive
Successful CVE-2026-88772 exploitation left two log artefacts:
In syslog, an SSL_HANDSHAKE_FAILURE with ClientVersion DTLSv1.0 and Reason "Handshake failure-Internal Error".
In /var/log/messages, an NSPPE termination logged by pitboss, the watchdog daemon that restarts crashed processes.
Also look for httpd.conf changes that make the web server treat other file types as PHP, such as AddHandler application/x-httpd-php .deb.
GTIG publishes these YARA rules: G_APT_Backdoorwebshell_WHIPSHOT_1, G_APT_Tunneler_SLAPSHOT_1, and a hunting rule for suspicious NetScaler PHP configuration. This page links to them rather than copying them.
As of 29 September, Nextron has three rules in the THOR Preview channel:
LOG_SUSP_EXPL_CVE_2026_88771_Sep26
WEBSHELL_CSS_PassThrough_Sep26, which detects the webshell's behaviour, not only its filename
EXPL_CVE_2026_88772_POC_Sep26, which detects PoC artefacts, not attacks on an appliance
Nextron also published a YAML filesystem IOC set derived from Citrix's scanner script. It covers 12 of the script's checks, consolidated into four file rules. It leaves out the 22 checks that depend on logs, configuration or runtime state.
Preview-channel rules have not finished manual QA, so expect more false positives than with stable rules. A match is a lead for investigation, not proof of compromise.
watchTowr Detection Artefact Generators Active tests
These tools send traffic to an appliance. Run them only against systems you own or administer. This page links to the repositories. It does not reproduce their code or payloads.
Beaumont describes the other GitHub "PoCs" he has seen as fake AI slop. That is his characterisation. [Beaumont]
Remediation
Fixed builds (Citrix CTX697096)
Fixed builds as listed in CTX697096
Fixed build, exactly as listed by Citrix
Source: Citrix CTX697096. Use the bulletin as the authority for which build applies to your deployment.
After patching
Check for compromise and preserve evidence before you patch. Mandiant's CTO, Charles Carmakal, says customers should examine their systems for compromise *before* upgrading/patching. [The Register] Unit 42 lists the evidence to capture: [Unit 42]
a NetScaler VPX instance snapshot
logs on remote syslog servers and in NetScaler Console
a technical support bundle
a packet engine core dump
Patching and restarting can destroy this evidence.
Patch to a fixed build from the table above.
Hunt for compromise. Check for:
webshells, including the GreyNoise path and alias above
changes to httpd.conf, such as an unexpected AliasMatch
unusual permissions on /bin/sh, such as setuid or setgid
Assume activity may be weeks old. Beaumont says slow disclosure means attackers have been active for weeks. [Beaumont]
Patching closes the vulnerabilities. It does not reverse a compromise that already happened. This page does not give remediation commands or guarantees. Follow Citrix and your national CSIRT.
Sources
Every link below is the exact URL from the compiled dataset. IFIN, Truesec, GTIG/Mandiant, Nextron, The Register, Unit 42, the Dutch government letter and two more Beaumont posts were added later, on 29 September. Links marked verification pending did not load in an automated check at build time. The URL has been kept unchanged, not replaced. For all other links, the check only showed that the page loaded, not that its content was reviewed.
Other government advisories cited in the dataset, with no URL supplied: Canada, HKCERT, ACSC.