Critical Citrix NetScaler ADC / NetScaler Gateway

PitScaler - Citrix NetScaler Zero-Day Crisis

Two NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, were exploited in the wild before disclosure. Both are rated CVSS 4.0 9.5 Critical. Citrix fixed them in bulletin CTX697096 together with six other CVEs. [Citrix CTX697096] [CISA]

Confirmed exploited zero-days
2

CVE-2026-88771, CVE-2026-88772

CVEs in bulletin CTX697096
8

CVE-2026-88771 to -88778

Public disclosure

15:51 UTC, per GreyNoise

CISA KEV federal deadline

A deadline that was still ahead at snapshot time

Official Citrix bulletin and government advisories Research third-party technical analysis Telemetry sensor data (GreyNoise) Reported Beaumont's posts, community and press reports. These are claims and have not been independently verified.

Overview

What happened

Citrix published bulletin CTX697096 with fixes for eight NetScaler ADC and Gateway CVEs on 27 September 2026. [Citrix] The same day, CISA added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities catalog, with a federal remediation deadline of 30 September. [CISA]

Google GTIG and Mandiant report that CVE-2026-88772 has been exploited since at least early September. Organisations in North America and Europe in government, financial services, education, and legal and professional services were likely affected. The attackers used new custom malware: WHIPSHOT, a PHP webshell, and SLAPSHOT, a Python tunneler that reaches into internal networks. [GTIG/Mandiant]

Unit 42 counted 50,277 exposed NetScaler instances that could potentially be vulnerable, as of 27 September, from its Cortex Xpanse data. That is an exposure count, not a count of compromised systems. [Unit 42]

GreyNoise sensors recorded exploitation from one IP on 24 September, three days before public disclosure. GreyNoise's retro-hunt found no other exploitation sessions before disclosure. That result covers GreyNoise's own sensors, not all internet activity. [GreyNoise] [GreyNoise Chronicle]

The name

Kevin Beaumont (@GossiTheDog) coined the name "PitScaler" on 28 September. [Beaumont] It refers to the root cause: a Perl script writing to /tmp. CERT-EU's writeup title describes this as Citrix taking execute logging a bit too literally. [CERT-EU]

Reported by Beaumont Unverified claims

  • Chaining CVE-2026-88771, -88772 and -88773 gives unauthenticated RCE in the default appliance configuration. Webshells were dropped throughout September. He calls the attackers Probably nation state aligned. [post]
  • He says he is tracking over 100 victim organisations, each with a unique webshell. [post]
  • His firmware version scanning suggests fewer than 10% of boxes are patched. [post]

These figures are Beaumont's own public statements and have not been independently confirmed.

The eight CVEs in CTX697096

Citrix's bulletin lists all eight CVEs. Only CVE-2026-88771 and CVE-2026-88772 are confirmed exploited. [Citrix] [CISA]

Timeline

Times are UTC unless marked otherwise. Events without a time show only their date. Expand an event to see its sources.

    Public IoCs Public / TLP:CLEAR only

    This table only contains indicators that have been published openly. The Sharing column shows each source's own marking. [GreyNoise] [IFIN] [Truesec] [GTIG/Mandiant]

    How to read these. Each indicator was observed by the source named in its row. None of them is a universal indicator for every victim. Beaumont reports that webshell names and attacker IPs are unique per victim. [Beaumont] [Beaumont] An empty search result proves nothing.

    Publicly released indicators for NetScaler CVE-2026-88771 and CVE-2026-88772 exploitation
    TypeExact valueSourceContextCaveatSharing

    Post-exploitation behaviour observed by GreyNoise

    A Reddit user described one sample of the .ctxs.receiver file, and IFIN relayed the description. This is unconfirmed. [IFIN]

    The token likely differs per victim, so search the file's content rather than relying on its hash.

    Source: GreyNoise, "Swarming Against Citrix 0-Day Exploitation". Victim-specific names and IPs from later IR-vendor writeups are deliberately left out. Beaumont warns that publishing them exposes organisations that have not yet remediated. [Beaumont]

    Detection and hunting

    A clean scan does not clear a host. A checker can miss a planted webshell, especially when logs have rotated or permissions were changed.

    CERT-EU hunting patterns Passive

    • Base64 strings in the User-Agent header that start with INDEX:.
    • PPE missed too many heartbeats entries in authentication logs.
    • Check that httpd.conf is intact, for example look for the AliasMatch in the IoC table.

    Source: CERT-EU writeup

    CIRCL TR-100 Config check

    For each CVE, CIRCL gives CLI commands that check whether your appliance's configuration exposes it. Run them on appliances you administer.

    Source: CIRCL TR-100

    Citrix Console IoC checker Limits per Beaumont

    • Available only through support or under NDA. [post]
    • Incomplete: it does not check for suid on /bin/sh. [post]
    • Misses earlier semi-successful attempts once logs have rotated. [post]

    Beaumont also says Some really big orgs are backdoored after patching still. He has asked national CSIRTs (NCSCs) to publish a detection script. [post]

    GTIG/Mandiant artefacts and YARA Passive

    Successful CVE-2026-88772 exploitation left two log artefacts:

    • In syslog, an SSL_HANDSHAKE_FAILURE with ClientVersion DTLSv1.0 and Reason "Handshake failure-Internal Error".
    • In /var/log/messages, an NSPPE termination logged by pitboss, the watchdog daemon that restarts crashed processes.

    Also look for httpd.conf changes that make the web server treat other file types as PHP, such as AddHandler application/x-httpd-php .deb.

    GTIG publishes these YARA rules: G_APT_Backdoorwebshell_WHIPSHOT_1, G_APT_Tunneler_SLAPSHOT_1, and a hunting rule for suspicious NetScaler PHP configuration. This page links to them rather than copying them.

    Source: GTIG/Mandiant advisory

    Nextron THOR Scanner rules

    As of 29 September, Nextron has three rules in the THOR Preview channel:

    • LOG_SUSP_EXPL_CVE_2026_88771_Sep26
    • WEBSHELL_CSS_PassThrough_Sep26, which detects the webshell's behaviour, not only its filename
    • EXPL_CVE_2026_88772_POC_Sep26, which detects PoC artefacts, not attacks on an appliance

    Nextron also published a YAML filesystem IOC set derived from Citrix's scanner script. It covers 12 of the script's checks, consolidated into four file rules. It leaves out the 22 checks that depend on logs, configuration or runtime state.

    Preview-channel rules have not finished manual QA, so expect more false positives than with stable rules. A match is a lead for investigation, not proof of compromise.

    Source: Nextron Systems

    watchTowr Detection Artefact Generators Active tests

    These tools send traffic to an appliance. Run them only against systems you own or administer. This page links to the repositories. It does not reproduce their code or payloads.

    Beaumont describes the other GitHub "PoCs" he has seen as fake AI slop. That is his characterisation. [Beaumont]

    Remediation

    Fixed builds (Citrix CTX697096)

    Fixed builds as listed in CTX697096
    Fixed build, exactly as listed by Citrix

    Source: Citrix CTX697096. Use the bulletin as the authority for which build applies to your deployment.

    After patching

    1. Check for compromise and preserve evidence before you patch. Mandiant's CTO, Charles Carmakal, says customers should examine their systems for compromise *before* upgrading/patching. [The Register] Unit 42 lists the evidence to capture: [Unit 42]
      • a NetScaler VPX instance snapshot
      • logs on remote syslog servers and in NetScaler Console
      • a technical support bundle
      • a packet engine core dump
      Patching and restarting can destroy this evidence.
    2. Patch to a fixed build from the table above.
    3. Hunt for compromise. Check for:
      • webshells, including the GreyNoise path and alias above
      • changes to httpd.conf, such as an unexpected AliasMatch
      • unusual permissions on /bin/sh, such as setuid or setgid
      Use the CERT-EU and CIRCL guidance. [CERT-EU] [CIRCL] [GreyNoise]
    4. Assume activity may be weeks old. Beaumont says slow disclosure means attackers have been active for weeks. [Beaumont]

    Patching closes the vulnerabilities. It does not reverse a compromise that already happened. This page does not give remediation commands or guarantees. Follow Citrix and your national CSIRT.

    Sources

    Every link below is the exact URL from the compiled dataset. IFIN, Truesec, GTIG/Mandiant, Nextron, The Register, Unit 42, the Dutch government letter and two more Beaumont posts were added later, on 29 September. Links marked verification pending did not load in an automated check at build time. The URL has been kept unchanged, not replaced. For all other links, the check only showed that the page loaded, not that its content was reviewed.

    Other government advisories cited in the dataset, with no URL supplied: Canada, HKCERT, ACSC.