- Type
- Improper input validation; unauthenticated remote command execution. [1]
- Exposure
- Affects the DEFAULT configuration; no features need to be enabled. [1]
- Root cause (CERT-EU)
- /netscaler/ns_monuploadd_err.pl passes unsanitised input to grep+exec; a tail -1 race condition is also involved. [19]
- Status
- Exploited in the wild; in CISA KEV since Sep 27. [1][5]
Critical Citrix NetScaler ADC / NetScaler Gateway
PitScaler - Citrix NetScaler Zero-Day Crisis
Two Citrix NetScaler ADC and NetScaler Gateway vulnerabilities, CVE-2026-88771 and CVE-2026-88772, were exploited in the wild as zero-days before disclosure. Both allow unauthenticated remote code execution (RCE) and are rated CVSS 4.0 9.5 Critical. Governments and companies across Europe shut down or disconnected their NetScalers while waiting for a patch. [17][55] Citrix fixed them in bulletin CTX697096 together with six other CVEs. [1][5]
- Confirmed exploited zero-days
- 2
- CVEs in bulletin CTX697096
- 8
- Public disclosure
- CISA KEV federal deadline
CVE-2026-88771, CVE-2026-88772
CVE-2026-88771 to -88778
15:51 UTC, per GreyNoise
Due on the snapshot date
Key facts
| Products | Citrix NetScaler ADC and NetScaler Gateway (customer-managed) |
|---|---|
| Confirmed exploited | CVE-2026-88771 (unauthenticated RCE, default configuration) and CVE-2026-88772 (DTLS memory overflow, RCE or DoS), both CVSS 4.0 9.5 and in CISA KEV [1][12] |
| Also in the bulletin | CVE-2026-88773 to CVE-2026-88778 (no exploitation reported) |
| Exploited since | At least early September 2026. eSentire saw exploitation on 5 Sep, and ACSC advises reviewing from 4 Sep [32][11] |
| Fixed builds | 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, 13.1.37.279 FIPS/NDcPP and later (details) |
| First action | Preserve evidence and check for compromise, then patch. Patching does not remove a backdoor (detection) |
| Attribution | None public; no vendor has named an actor [27] |
| This page | Independent historical snapshot, not a live feed. Every claim is sourced and labelled official, research, telemetry or reported (methodology) |
Overview: exploited NetScaler zero-day vulnerabilities
What happened
Citrix published bulletin CTX697096 with fixes for eight NetScaler ADC and Gateway CVEs on 27 September 2026. [1] The same day, CISA added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities catalog, with a federal remediation deadline of 30 September. [5]
Google GTIG and Mandiant report that CVE-2026-88772 has been exploited since at least early September. Organisations in North America and Europe in government, financial services, education, and legal and professional services were likely affected. The attackers used new custom malware: WHIPSHOT, a PHP webshell, and SLAPSHOT, a Python tunneler that reaches into internal networks. [25]
eSentire's incident response saw CVE-2026-88771 exploited as early as 5 September. In one intrusion a webshell was installed and operated from that day, with signs of data exfiltration and lateral movement into the internal network. eSentire advises treating appliances that were Internet-facing and unpatched in early September as potentially compromised. [32]
Unit 42 counted 50,277 exposed NetScaler instances that could potentially be vulnerable, as of 27 September, from its Cortex Xpanse data. That is an exposure count, not a count of compromised systems. [63]
Censys detects NetScaler ADC or Gateway on 42,735 hosts, as of 28 September. The largest shares are in the US (32%) and Germany (13%). Shadowserver reports more than 20,000 instances exposed and potentially at risk. Both are exposure counts, not confirmed vulnerable or compromised systems. [41][65][64]
Who is affected and who responded
- Victims: GTIG/Mandiant say organisations in North America and Europe in government, financial services, education, and legal and professional services were likely affected. [25][62] watchTowr CEO Benjamin Harris says there is no clear trend yet by industry or organisation size. Mandiant says dozens of organisations were hit, telecommunications among them. [68][62]
- US: CISA added both CVEs to KEV and gave federal agencies until 30 September. [5] Beaumont publicly pointed the NSA at one of its Citrix hosts. The host has been validated as NSA-operated; whether it is compromised is not verified. [50]
- Netherlands: NCSC-NL rates the advisory as high probability, high damage. Central government applied "loskoppelen tenzij" (disconnect unless) from 26 September. The Ministry of the Interior took all Citrix environments offline, and the Amphia (Breda) and ETZ (Tilburg) hospitals closed their patient portals after Z-CERT warned the healthcare sector. [67][71][6][17]
- Denmark: Danish government agencies, among them PET, the Armed Forces and the police, took their NetScalers offline from Friday 25 September, two days before Citrix's disclosure. Copenhagen Airport also switched off its Citrix environment, and Shodan shows some Danish systems going dark from 23 September, according to Ingeniøren. The Danish Defence Intelligence Service (FE) warned NetScaler users on 27 September. DKCERT, the CERT for Danish universities and research institutions, followed on 29 September. [66][14]
- UK and EU: NCSC-UK published an alert, and NHS England's cyber security operations centre issued alert CC-4858, rating further exploitation "almost certain". CERT-EU published Security Advisory 2026-014 and a technical writeup with hunting guidance, and Luxembourg's CIRCL published a set of per-CVE configuration checks. [15][13][7][19][16]
- Australia: ACSC says Australian organisations have confirmed exploitation, and advises reviewing for compromise since at least 4 September. [11]
- Canada, Hong Kong and Singapore: CCCS, HKCERT and CSA Singapore issued advisories. [9][11][10][8]
GreyNoise sensors recorded exploitation from one IP on 24 September, three days before public disclosure. GreyNoise's retro-hunt found no other exploitation sessions before disclosure. That result covers GreyNoise's own sensors, not all Internet activity. [36][37]
The name
Kevin Beaumont (@GossiTheDog) coined the name "PitScaler" on 28 September. [47] It refers to the root cause: a Perl script writing to /tmp. CERT-EU's writeup title describes this as Citrix taking execute logging a bit too literally
. [19]
Reported by Beaumont Unverified claims
- Chaining CVE-2026-88771, -88772 and -88773 gives unauthenticated RCE in the default appliance configuration. Webshells were dropped throughout September. He calls the attackers
Probably nation state aligned
. [44] The quote was checked against the post on 29 September. GTIG/Mandiant separately confirm webshells since at least early September. [25] No one else has confirmed the CVE-2026-88773 link or the nation-state assessment. watchTowr says no attribution has been made public. [62] - He says he is tracking over 100 victim organisations, each with a unique webshell. [47]
- His firmware version scanning suggests fewer than 10% of boxes are patched. [49]
These figures are Beaumont's own public statements and have not been independently confirmed.
The eight NetScaler vulnerabilities (CVEs) in CTX697096
Citrix's bulletin lists all eight CVEs with CVSS 4.0 scores and preconditions, and NCSC-NL's advisory NCSC-2026-0394 gives the same figures. Only CVE-2026-88771 and CVE-2026-88772 are confirmed exploited. [6][1][5]
- Type (Citrix)
- Memory overflow leading to RCE or DoS when DTLS is enabled. [1]
- Exposure
- DTLS is ON by default on VPN virtual servers unless the admin sets -dtls OFF. [1]
- Campaign (GTIG/Mandiant)
- Exploited since at least early September. Exploitation crashes the NSPPE packet engine and gives root-level access. Organisations in North America and Europe in government, financial services, education and legal/professional services were likely impacted. [25]
- Mechanics (watchTowr)
- Preauth heap overflow in the DTLS stack (nsppe process); 137,825 bytes written past the buffer; control gained via an overwritten global list pointer, then a ROP chain calling mprotect and jumping to shellcode - full RCE, not just DoS. [22]
- Status
- Exploited in the wild; in CISA KEV since Sep 27. [1][5]
- Type
- HTTP request smuggling (CWE-444). [1][6]
- Precondition
- HTTP configuration enabled on NetScaler ADC or Gateway. No authentication or user interaction needed (NCSC-NL). [1][6]
- Role (Beaumont)
- Used in a chain with CVE-2026-88771 and CVE-2026-88772 in the original attacks, according to Beaumont. Not independently confirmed; no source reports it exploited on its own. [44]
Timeline
Times are UTC unless marked otherwise. Events without a time show only their date. Expand an event to see its sources.
- Research
eSentire: CVE-2026-88771 exploited as early as 5 September
eSentire TRU incident response saw exploitation of Internet-facing NetScaler Gateways from 5 Sep, more than three weeks before disclosure: base64 PHP staged in the access log via fake /vpn/media/*.ico requests, then executed through a crafted login username. In one intrusion a .deb-variant webshell was installed and operated from 5 Sep, with signs of data exfiltration and lateral movement to internal virtual desktops and back to the appliance over SSH.
Sources: [32]
- Official advisory Validated
CVE IDs reserved
NetScaler reserves CVE-2026-88771 and CVE-2026-88772 at 07:14 UTC. The records were published on 27 Sep at 16:02 and 16:09 UTC.
Validated against the CVE record on 29 Sep.
- Reported observation
Danish NetScalers start going offline
Ingeniøren's review of Shodan data shows several Danish NetScaler systems switched off from 23 Sep, four days before Citrix's public disclosure.
Sources: [66]
- Telemetry
GreyNoise sensors see exploitation from a single IP
149.104.78.141: 3 sessions 07:32:19-07:32:20 UTC. IP flagged "suspicious" (Citrix ADC Gateway Login Panel Crawler), then "malicious" (Generic ${IFS} Use in RCE Attempt; CitrixBleed 2 attempt). Later retro-tagged as CVE-2026-88771. GreyNoise's retro-hunt found no other exploitation sessions before disclosure - this covers GreyNoise sensors only.
- Reported observation Validated
Danish government agencies shut down their NetScalers
Danish agencies, among them PET, the Armed Forces and the police, took their Citrix NetScaler environments offline from Friday 25 Sep, two days before Citrix disclosed the vulnerabilities. Ingeniøren later reported the shutdowns from Shodan data; none of the agencies would explain why.
The Friday 25 Sep shutdown was validated independently on 30 Sep.
Sources: [66]
- Official advisory
NCSC-NL confidentially warns Dutch organisations
On the afternoon of Friday 25 Sep, after a tip from a European partner, NCSC-NL confidentially informed companies and organisations, including central government, about two NetScaler zero-days being exploited outside the Netherlands, before any patch existed. Dark Reading reports that a copy of the pre-notification, marked TLP:AMBER+STRICT, was briefly posted on Reddit and then deleted. According to BleepingComputer, the notice said Citrix found the vulnerabilities while investigating incidents at customers and filed a notification under the EU Cyber Resilience Act.
- Reported observation Validated
r/Citrix "Netscaler leak?" thread
User FastFredNL opens the thread at 06:43:22 UTC (08:43 CEST), reporting that an IT provider advised shutting NetScalers down immediately. It becomes the first public gathering point, with admins reporting similar unofficial advice over the weekend. Dark Reading dates the first reports to 25 Sep, but the thread itself was posted on 26 Sep.
Post timestamp checked on the thread itself (30 Sep). The shutdown advice is consistent with the Dutch government letter to parliament.
- Research
watchTowr: two unpatched RCE zero-days, found during forensics
Two vulnerabilities - both RCE. Unpatched, 0days. Exploited in-the-wild - discovered during forensics.
watchTowr adds that Citrix comms and patches are expected early the following week.
Sources: [34]
- Reported observation
IFIN opens a public tracking thread
IFIN starts compiling public reporting and observables for the NetScaler zero-days; it later states that all observables it shares were shared without restriction.
Sources: [40]
- Reported observation
watchTowr: pull NetScaler appliances offline immediately
Please, take this seriously and pull NetScaler appliances offline immediately.
watchTowr publicly warns that credible rumours of unpatched NetScaler RCEs are circulating; later that day CEO Benjamin Harris says the rumours are confirmed and urges admins to pull NetScaler appliances offline immediately.
Sources: [70]
- Reported observation
Dutch hospitals Amphia and ETZ close patient portals
Patients of Amphia (Breda) and Elisabeth-TweeSteden Ziekenhuis (Tilburg) cannot log in to their portals; other Dutch hospitals report problems too. That evening Z-CERT, the Dutch healthcare CERT, says it warned the sector about critical vulnerabilities in Citrix NetScaler and advised temporarily switching the system off.
Sources: [71]
- Official advisory
Public disclosure; Citrix publishes CTX697096 with fixes
Disclosure time per GreyNoise. The bulletin covers 8 CVEs. watchTowr notes the patch it analysed was dated 24 Sep, suggesting Citrix knew of the exploitation the week before.
- Official advisory
Citrix announces the bulletin on r/Citrix
A Citrix staff account (CTX-Michael) posts a CRITICAL UPDATE in r/Citrix linking the CTX697096 bulletin and the Citrix community blog post with its IoC section, and quoting that exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated deployments has been observed.
- Telemetry
GreyNoise deploys CVE-specific tag
Tag deployed 20:28:39 UTC; the 24 Sep sessions are retro-tagged as CVE-2026-88771.
- Official advisory Validated
CISA adds CVE-2026-88771 and CVE-2026-88772 to KEV
Both were added on 27 Sep with a federal remediation deadline of 30 Sep. The 21:30 UTC release time comes from the compiled dataset and was not found in the sources checked.
Dates validated against the KEV catalog feed on 29 Sep.
- Telemetry
Unit 42: 50,277 exposed instances
Palo Alto Networks Cortex Xpanse identifies 50,277 exposed NetScaler instances that could potentially be vulnerable (update posted 4:15 p.m. PT). Exposure, not confirmed compromise.
Sources: [63]
- Official advisory
Danish Defence Intelligence (FE) and CERT-EU warn NetScaler users
The Danish Defence Intelligence Service sent a warning urging NetScaler users to update, per Ingeniøren. CERT-EU published Security Advisory 2026-014 recommending an immediate update of all customer-managed appliances and enabling Enhanced ISN Generation where TCP is configured.
- Reported observation
Beaumont: three CVEs chained, webshells all September
The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained. It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September. Probably nation state aligned
Beaumont's claim; attribution not independently verified.
Sources: [44]
- Reported observation
Beaumont: patches live, detection script behind NDA
patching alone doesn't remove the backdoors being placed
Patches are live on the main support site; Citrix's detection script is locked behind NDA/support.
Sources: [45]
- Reported observation Validated
Beaumont: Console check misses earlier attempts
The NetScaler Console check misses earlier semi-successful attempts because it relies on logs not having rotated; he adds that the activity is weeks old because of slow disclosure.
Validated independently on 29 Sep.
Sources: [46]
- Official advisory
NHS England alert CC-4858
NHS England's National CSOC rates the threat High and assesses further exploitation as almost certain. It strongly recommends a compromise assessment before patching, since patching first may delete evidence, and warns that end-of-life 12.1 and 13.0 releases are likely vulnerable and receive no fix. Published 10:40 UK time.
Sources: [15]
- Reported observation
Beaumont names it "PitScaler"
I'm tracking over 100 victim orgs now. Each one has a unique webshell which can't be scanned for remotely unless you're the attacker. It's espionage.
Victim count is Beaumont's claim, not independently verified.
Sources: [47]
- Reported observation Validated
Beaumont: Citrix checker incomplete
Some really big orgs are backdoored after patching still
The checker does not check for suid on /bin/sh; Beaumont calls on NCSCs to publish a detection script.
The missing suid /bin/sh check was validated independently on 29 Sep. The claim about big organisations still being backdoored is not independently verified.
Sources: [48]
- Reported observation
Press covers the weekend shutdown warnings
BleepingComputer, SecurityWeek, The Record and CyberScoop cover the story.
- Research
CERT-EU technical writeup on CVE-2026-88771
"Taking 'execute logging' a bit too literally" - root cause, attack chain and hunting guidance.
Sources: [19]
- Official advisory
Government advisories worldwide
NCSC-NL NCSC-2026-0394 [H/H], NCSC-UK, CSA Singapore AL-2026-129, plus Canada, HKCERT, ACSC, and CIRCL TR-100 with per-CVE config-check CLI commands.
- Telemetry
GreyNoise publishes TLP:CLEAR IoC set
"Swarming Against Citrix 0-Day Exploitation" - the first public IoC set in this compiled dataset as of 29 Sep, with a companion Chronicle timeline.
- Research
watchTowr Labs part 1 (CVE-2026-88771)
"Oh Look, the Foot Gun Went Off Again", published with a Detection Artefact Generator (PoC-class tool).
- Telemetry
Censys and Shadowserver count exposed NetScalers
Censys detects NetScaler ADC or Gateway on 42,735 hosts and 323,527 web properties; these are exposed instances, not confirmed-vulnerable counts. Shadowserver reports more than 20,000 instances exposed and potentially at risk.
- Telemetry
Lupovis honeypots see exploitation minutes after the public PoC
Lupovis says its sensors recorded live CVE-2026-88771 exploitation attempts within minutes of watchTowr releasing its PoC; the attempts were opportunistic, from several distinct actors.
- Research
First public detection rules
Elastic merges a rule for NetScaler log-poisoning command injection; Corelight publishes Zeek hunting queries. Sigma and Nuclei pull requests follow (28-29 Sep, still unmerged at snapshot time).
- Research
Truesec publishes potential C2 IPs
Truesec lists 104.248.244.66, 139.180.152.138 and 77.83.199.39 as potential C2 IPs it has observed.
Sources: [24]
- Official advisory
ACSC alert; Australian organisations later confirm exploitation
Australia's ACSC publishes an alert on 28 Sep. In an update it says Australian organisations have since confirmed exploitation, and recommends reviewing for evidence of compromise since at least 4 Sep 2026.
Sources: [11]
- Reported observation
Dutch ministry and hospitals take systems offline
The Dutch Ministry of the Interior took all Citrix environments offline over the weekend; patients of two major hospitals (Amphia and ETZ) could not view their records, and Frisius MC in Leeuwarden shut down some digital systems as a precaution (SDxCentral, citing Techzine).
Sources: [67]
- Reported observation
Beaumont: mass exploitation
#PitScaler is under mass exploitation, seeing it spray and pray now. I've done some firmware version scanning, fewer than 10% of boxes are patched
The <10% figure is Beaumont's own estimate, not independently verified.
Sources: [49]
- Reported observation Compromise unverified
Beaumont posts a public message to the NSA
do forensics on 103.41.70.207,vdicorp.nsa.gov
The domain resolves to that IP. That the host is an NSA-operated Citrix system has been validated independently. That it is compromised is Beaumont's implication and is not verified. This briefing does not identify any organisation as compromised, and these values are not listed as IoCs.
Sources: [50]
- Reported observation Validated
Beaumont: IR writeups expose victim-unique indicators
IR vendors are publishing PitScaler writeups containing victim-unique webshell names (.sig files) and attacker IPs, which he says lets him map victim orgs via network traffic. He warns that unremediated orgs' published webshell names can be used to access their boxes, and says one vendor uploaded its IR investigation to VirusTotal.
Validated independently on 29 Sep.
Sources: [51]
- Reported observation
The Register: government, banks and professional services targeted
Why Citrix took so long to disclose these vulnerabilities is a question only Citrix can answer
It reports GTIG/Mandiant findings that government, financial services, education and legal and professional services organisations in North America and Europe were likely hit. watchTowr CEO Benjamin Harris criticises the slow disclosure and says no attribution has been made public.
- Research
watchTowr Labs part 2 (CVE-2026-88772)
"Here We Go Again" (Sina Kheirkhah) - full RCE analysis plus a second Detection Artefact Generator.
- Research
Google GTIG / Mandiant: custom malware WHIPSHOT and SLAPSHOT
The CVE-2026-88772 campaign has been ongoing since at least early September. WHIPSHOT is a PHP webshell staged with a .deb disguise that hides base64 C2 in HTTP headers; SLAPSHOT is a Python TCP tunneler (open/push/pull/exch/close/ping) used to reach internal networks for reconnaissance and credential theft.
- Reported observation
BleepingComputer: credential theft and internal spread
It reports that attackers exploited CVE-2026-88772 to deploy webshells and tunneling malware, gain root, steal credentials and spread into internal networks, citing Mandiant. GTIG itself describes the credential theft and internal reconnaissance in at least one observed intrusion.
- Reported observation Validated
Mandiant CTO: check for compromise before patching
Given the active exploitation, NetScaler customers should prioritize examining their systems for compromise *before* upgrading/patching
Charles Carmakal on LinkedIn, as quoted by The Register.
Quote validated against a second, non-public source on 29 Sep.
Sources: [62]
- Research
Nextron releases THOR rules and a NetScaler filesystem IoC set
Three rules in the THOR Preview channel (higher false-positive rate than stable rules) plus a YAML IoC set derived from the filesystem checks in Citrix's scanner script. A match is a lead, not proof.
Sources: [26]
- Research
eSentire publishes first-hand IR findings and IoCs
Two webshell variants (.ico and .deb), 14 IPs and 2 SHA-256 hashes; the technique matches CERT-EU's description. eSentire advises treating appliances that were Internet-facing and unpatched in early September as potentially compromised until an integrity assessment shows otherwise.
Sources: [32]
- Telemetry
Defused: hundreds of decoy hits across multiple exploit paths
Defused reports hundreds of CVE-2026-88771 hits on its decoys in 24 hours via /nf/auth/doAuthentication.do, /cgi/login, /p/u/doLogon.do, /logon/LogonPoint/tmindex.html and User-Agent payloads on /. Observed follow-up: whoami/id to prove root, nx_verify.html marker files, curl/wget/fetch pulling a second stage, and blind DNS callbacks. Full IoCs are on Defused Radar (not reproduced here).
Sources: [42]
- Official advisory
DKCERT warns Danish universities and research institutions
DKCERT, the CERT for the Danish research and education network, reports two critical NetScaler zero-days exploited before a patch and notes that several administrators took systems offline before Citrix published details.
Sources: [14]
- Reported observation
Mandiant: dozens of organisations impacted
Cybersecurity Dive reports Mandiant CTO Charles Carmakal saying the actor deployed webshells and moved laterally into internal networks at some targets, with dozens of organisations impacted across North America and Europe, including telecommunications.
Sources: [68]
- Official advisory
Dutch government confirms preventive disconnection
Letter to parliament: on Saturday 26 Sep the CIO Rijk set the line "loskoppelen tenzij" (disconnect unless) for central government, and it was broadly applied; remote-work access has not yet been restored everywhere while the patch is tested and forensic investigation continues. Beaumont relays it at 18:32 UTC as "shut down all Citrix Netscalers".
- Reported observation
Ingeniøren: PET, Danish Defence and police shut down Citrix
Based on Shodan data, Ingeniøren reports that PET, the Danish Armed Forces, the Danish police and Copenhagen Airport, among many others, had to switch off their Citrix environments over the weekend. None of the agencies would explain why.
Sources: [66]
- Official advisory Deadline - upcoming
Deadline: CISA KEV federal remediation
Due on the snapshot date (30 Sep). A deadline, not an event.
Sources: [5]
Public IoCs Public / TLP:CLEAR only
This table only contains indicators that have been published openly. The Sharing column shows each source's own marking. [36][40][24][25]
- GreyNoise published its set on 28 September, marked TLP:CLEAR. GreyNoise has announced a longer "GreyNoise Labs" version, but the link on its blog was still a placeholder on 29 September.
- IFIN says the observables it shares were shared without restriction.
- Truesec's page is public and has no TLP marking.
- GTIG/Mandiant's blog is public and has no TLP marking. GTIG keeps its full IoC collection for registered GTI users only.
Indicators are not proof of compromise by themselves. Validate any hit against appliance logs, filesystem integrity, process history and configuration changes, following your incident-response procedure.
How to read these. Each indicator was observed by the source named in its row. None of them is a universal indicator for every victim. Beaumont reports that webshell names and attacker IPs are unique per victim. [47][51] An empty search result proves nothing.
| Type | Exact value | Source | Context | Caveat | Sharing |
|---|---|---|---|---|---|
| IPv4 | 149.104.78.141 | GreyNoise blog [36]; GreyNoise Visualizer [38]; eSentire TRU [32] | Exploitation source, Sep 24 (3 sessions 07:32:19-07:32:20 UTC). GreyNoise Visualizer on Sep 29: AS154177 LIGHT NODE LIMITED, Japan; not observed mass scanning in the past day. | Observed in GreyNoise sensor data; not a universal indicator for every victim. Beaumont reports attacker IPs vary per victim. eSentire also lists it as an exploitation source. | TLP:CLEAR |
| File path | /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver | GreyNoise blog [36] | Webshell path on disk | Observed in GreyNoise sensor data; not a universal indicator for every victim. Beaumont reports webshell names are unique per victim. | TLP:CLEAR |
| URL alias | receiver.min.css | GreyNoise blog [36] | Webshell alias | Observed in GreyNoise sensor data; not a universal indicator for every victim. | TLP:CLEAR |
| AliasMatch regex | receiver\.min\.[0-9a-f]+\.css | GreyNoise blog [36]; CERT-EU [19] | Apache config (httpd.conf) AliasMatch | Observed in GreyNoise sensor data; not a universal indicator for every victim. Pattern as published; also check httpd.conf integrity generally. | TLP:CLEAR |
| SHA-256 | 6f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7 | GreyNoise blog [36] | Webshell hash | Observed in GreyNoise sensor data; not a universal indicator for every victim. Per-victim webshells may differ. | TLP:CLEAR |
| GreyNoise tag | Citrix NetScaler CVE-2026-88771 Login Command Injection RCE Attempt | GreyNoise tag [39]; GreyNoise blog [36] | Sensor detection tag, created Sep 27. GreyNoise Visualizer on Sep 29: 76 unique IPs tagged between Sep 19 and Sep 29, all classified malicious. All are listed in this table; two are Cloudflare WARP exits, marked as such. | Classifies traffic seen by GreyNoise and community sensors only. Most tagged IPs also carry crawler and CitrixBleed 2 tags, so many look like opportunistic scanning. | TLP:CLEAR |
| SHA-256 | ed082f744f035035900f67edf438f2f7d0528ac501234f63d476d65273cdb9a1 | IFIN [40] | .ctxs.receiver webshell sample (237-byte PHP file) posted by a Reddit user, relayed by IFIN | Unconfirmed single-victim sample. The hardcoded token likely differs per victim, so the hash will too - match on file content, not hash. | Public, no restriction |
| IPv4 | 104.248.244.66 | Truesec [24]; IFIN [40] | Potential C2 IP observed by Truesec | IR-vendor observation. Beaumont reports attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host. | Public page, no TLP marking |
| IPv4 | 139.180.152.138 | Truesec [24]; IFIN [40]; eSentire TRU [32] | Potential C2 IP observed by Truesec; webshell delivery per eSentire | IR-vendor observation. Beaumont reports attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host. | Public page, no TLP marking |
| IPv4 | 77.83.199.39 | Truesec [24]; IFIN [40]; eSentire TRU [32] | Potential C2 IP observed by Truesec; webshell delivery per eSentire | IR-vendor observation. Beaumont reports attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host. | Public page, no TLP marking |
| IPv4 | 78.135.96.136 | IFIN [40] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. | Public, no restriction |
| IPv4 | 149.28.29.221 | IFIN [40] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. | Public, no restriction |
| IPv4 | 80.240.22.229 | IFIN [40] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. | Public, no restriction |
| IPv4 | 89.36.231.206 | IFIN [40] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. | Public, no restriction |
| IPv4 | 91.195.240.123 | IFIN [40] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. WHOIS: SEDO-NET, Sedo Domain Parking - a shared parking IP used by many unrelated parked domains. Expect heavy false positives; do not block on it alone. | Public, no restriction |
| IPv4 | 143.198.7.94 | Google GTIG / Mandiant [25] | Scanning and staging infrastructure | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| IPv4 | 157.254.167.12 | Google GTIG / Mandiant [25] | NetScaler exploitation and installation of a basic webshell backdoor | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| HTTP header | HTTP_NSC_LDAP | Google GTIG / Mandiant [25] | Inbound command execution header used by nsginstaller.deb | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| HTTP header | HTTP_NSC_CLIENTTYPE | Google GTIG / Mandiant [25] | Inbound command execution header used by nsgclient.sig | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| HTTP header | HTTP_X_UX / HTTP_X_UX_[0-9]+ | Google GTIG / Mandiant [25] | Chunked base64 transport headers used by WHIPSHOT | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| URI path | /vpn/media/nsgclient.ico / /vpn/media/*.ico | Google GTIG / Mandiant [25] | Masquerading icon request routed to a .sig webshell via AliasMatch | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| URI path | /vpn/scripts/linux/nsginstaller*.deb | Google GTIG / Mandiant [25] | Staging path for malicious PHP webshells | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| URI path | /vpn/scripts/linux/nsgclient*.deb | Google GTIG / Mandiant [25] | Staging path for malicious PHP webshells | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| URI path | /vpn/scripts/linux/*.php | Google GTIG / Mandiant [25] | Staging path for malicious PHP webshells | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| File path | /tmp/.uxdport | Google GTIG / Mandiant [25] | SLAPSHOT active port artefact | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| File path | /tmp/.uxdlock | Google GTIG / Mandiant [25] | SLAPSHOT process lock artefact | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| Config directive | AddHandler application/x-httpd-php .deb | Google GTIG / Mandiant [25] | httpd.conf change making .deb files run as PHP (GTIG persistence method A) | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Any AddHandler/AddType mapping a non-PHP extension to PHP indicates compromise, per GTIG. | Public blog, no TLP marking |
| Config directive | AddHandler application/x-httpd-php .sig | Google GTIG / Mandiant [25] | httpd.conf change making .sig files run as PHP (GTIG persistence method B) | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| Config directive | AliasMatch ^/vpn/media/(.+).ico$ /var/netscaler/gui/vpn/scripts/linux/$1.sig | Google GTIG / Mandiant [25] | Routes /vpn/media/*.ico requests to a .sig webshell with the same base name | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| File path | /netscaler/ns_gui/vpn/scripts/linux/ | Google GTIG / Mandiant [25] | Directory where WHIPSHOT was placed | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Legitimate client binaries live here too; look for ASCII text or PHP markers. | Public blog, no TLP marking |
| Filename pattern | nginstaller* | Google GTIG / Mandiant [25] | Installer webshell names seen across intrusions, often followed by a number | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. GTIG says filenames varied between victims. | Public blog, no TLP marking |
| Filename | nsgclient.sig | Google GTIG / Mandiant [25] | .sig webshell in VPN script directories | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| Filename | e6ee7c85.sig | Google GTIG / Mandiant [25] | GTIG example .sig webshell: reads base64 payloads from HTTP_NSC_CLIENTTYPE, runs them via eval() and returns a fake 404. Reached as /vpn/media/e6ee7c85.ico through the AliasMatch above | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Example from one intrusion; GTIG says filenames varied between victims, so absence proves nothing. | Public blog, no TLP marking |
| Log string | pitboss NOT restarting NSPPE | Google GTIG / Mandiant [25] | Watchdog message in /var/log/messages after an NSPPE crash | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Strongest when it follows a DTLSv1.0 SSL_HANDSHAKE_FAILURE on the same appliance. | Public blog, no TLP marking |
| String | UXD_IDLE_EXIT | Google GTIG / Mandiant [25] | SLAPSHOT idle-exit variable | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| Command | chmod u+s /bin/sh | Google GTIG / Mandiant [25]; GreyNoise blog [36] | Sets setuid on /bin/sh for persistent root; ls -l /bin/sh showing -rwsr-xr-x owned by root means modified | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| IPv4 | 138.199.200.90 | Help Net Security (Sep 29) [65] | Destination for data exfiltrated via log poisoning (Hetzner), seen by Lupovis | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. | Public article, no TLP marking |
| IPv4 | 138.28.234.38 | Lupovis (@LupovisDefence) on X, Sep 28 [43]; Beazley Security advisory (updated Sep 29) [27] | Exploitation with attempted DNS exfiltration (Lupovis) | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. | Public article, no TLP marking |
| IPv4 | 82.167.14.7 | Beazley Security advisory (updated Sep 29) [27]; GreyNoise tag [39]; eSentire TRU [32] | Exploitation check that writes a test marker (Lupovis); exploitation source per eSentire; also tagged by GreyNoise | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. May be a researcher-style check. | Public article, no TLP marking |
| IPv4 | 85.203.46.191 | Beazley Security advisory (updated Sep 29) [27]; GreyNoise tag [39] | Reconnaissance (Lupovis) | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. WHOIS netname Express-Equinix-London; GreyNoise tags it as VPN, so likely a commercial VPN exit shared by many users. | Public article, no TLP marking |
| IPv4 | 154.217.251.226 | Beazley Security advisory (updated Sep 29) [27]; GreyNoise tag [39] | CVE-2026-88772 scanning (Lupovis); also tagged by GreyNoise | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. | Public article, no TLP marking |
| IPv4 | 194.26.29.88 | Corelight [28] | Host of the reverse shell documented by Corelight (WHOIS: Media Land LLC, RU) | Reverse-shell infrastructure; hunt for connections from NetScaler NSIP/SNIP addresses. | Public blog, no TLP marking |
| DNS pattern | *.instances.httpworkbench.com | Help Net Security (Sep 29) [65]; Beazley Security advisory (updated Sep 29) [27] | Outbound lookups from a NetScaler suggest an out-of-band callback (Lupovis hunt advice) | httpworkbench.com is a public HTTP/DNS testing service, also used by researchers. Hunt signal only when the lookup comes from a NetScaler; do not block the apex. | Public article, no TLP marking |
| HTTP request pattern | POST /nf/auth/doAuthentication.do with body containing "pitboss PPE unexpectedly died NSPPE" | Help Net Security (Sep 29) [65] | Log-poisoning exploitation attempt (Lupovis hunt advice) | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. | Public article, no TLP marking |
| URI path | /nf/auth/doAuthentication.do | Defused (@DefusedCyber) on X, Sep 29 [42]; Help Net Security (Sep 29) [65] | CVE-2026-88771 exploitation attempts seen on Defused decoys (any logged field works) | Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. | Public post, no TLP marking |
| URI path | /cgi/login | Defused (@DefusedCyber) on X, Sep 29 [42] | CVE-2026-88771 exploitation attempts seen on Defused decoys | Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. | Public post, no TLP marking |
| URI path | /p/u/doLogon.do | Defused (@DefusedCyber) on X, Sep 29 [42] | CVE-2026-88771 exploitation attempts seen on Defused decoys | Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. | Public post, no TLP marking |
| URI path | /logon/LogonPoint/tmindex.html | Defused (@DefusedCyber) on X, Sep 29 [42] | CVE-2026-88771 exploitation attempts seen on Defused decoys | Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. | Public post, no TLP marking |
| HTTP header | User-Agent (payload in the header on requests to /) | Defused (@DefusedCyber) on X, Sep 29 [42]; CERT-EU [19] | CVE-2026-88771 exploitation attempts seen on Defused decoys | Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. CERT-EU separately flags base64 User-Agent strings starting with INDEX:. | Public post, no TLP marking |
| Filename | nx_verify.html | Defused (@DefusedCyber) on X, Sep 29 [42] | Marker file dropped to tag vulnerable boxes for a target list (Defused) | Also written by testers; means the box was reached and is exploitable, not necessarily that an actor installed a backdoor. | Public post, no TLP marking |
| SHA-256 | 5ea5ea61e9062822bee3f66ef5ff47c217178d9e31936ad6daf10c5dfae44d12 | eSentire TRU [32] | PHP webshell, .ico variant (publicly on VirusTotal per eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| SHA-256 | 7add390ceee4a1373211b3e340451b34f08965fc4d805f94c9b8cebdc0775774 | eSentire TRU [32] | PHP webshell, .deb variant (not in public repositories per eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| File path | /var/netscaler/gui/vpn/scripts/linux/*.sig | eSentire TRU [32]; Google GTIG / Mandiant [25] | .ico-variant webshell location (eSentire); also matches GTIG method B | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| HTTP request pattern | GET /vpn/media/*.ico with base64 PHP (starting "PD9") appended to the User-Agent | eSentire TRU [32]; CERT-EU [19] | Payload staging via the access log (eSentire; matches CERT-EU technique) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 34.90.151.231 | eSentire TRU [32] | Reconnaissance and webshell delivery (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. Google Cloud address space; may be reassigned. | Public advisory, no TLP marking |
| IPv4 | 31.56.197.72 | eSentire TRU [32] | Payload host (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 64.94.85.67 | eSentire TRU [32]; GreyNoise tag [39] | Payload host (eSentire); also tagged by GreyNoise | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 23.27.143.20 | eSentire TRU [32] | Payload host (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 62.133.62.80 | eSentire TRU [32] | Payload host (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 144.172.108.78 | eSentire TRU [32] | Exploitation source (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 185.156.46.162 | eSentire TRU [32]; GreyNoise tag [39] | Exploitation source (eSentire); also tagged by GreyNoise | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. GreyNoise tags it as VPN; may be shared. | Public advisory, no TLP marking |
| IPv4 | 153.75.82.220 | eSentire TRU [32]; GreyNoise tag [39] | Exploitation source (eSentire); also tagged by GreyNoise | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 216.203.21.233 | eSentire TRU [32]; GreyNoise tag [39] | Exploitation source (eSentire); also tagged by GreyNoise | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 185.243.41.247 | eSentire TRU [32] | Campaign infrastructure (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| Network | UDP/443 (DTLSv1.0) | Google GTIG / Mandiant [25] | Delivery protocol for the CVE-2026-88772 exploit (GTIG) | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Legitimate DTLS VPN traffic uses the same port; baseline normal DTLS sources. | Public blog, no TLP marking |
| Config directive | Alias /logon/LogonPoint/custom/receiver.min.css | Beazley Security Labs [33]; GreyNoise blog [36] | httpd.conf route to the .ctxs.receiver webshell (GreyNoise, via Beazley) | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. | Public advisory, no TLP marking |
| Config directive | AliasMatch ^/logon/LogonPoint/custom/receiver\.min\.[0-9a-f]+\.css$ | Beazley Security Labs [33]; GreyNoise blog [36] | httpd.conf route variant to the webshell (GreyNoise, via Beazley) | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. | Public advisory, no TLP marking |
| Config directive | php_flag engine on (changed from off) plus a SetHandler block for the webshell file | Beazley Security Labs [33]; CERT-EU [19] | PHP enabled for the webshell in httpd.conf (GreyNoise, CERT-EU, via Beazley) | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. Compare /etc/httpd.conf with a clean appliance on the same build. | Public advisory, no TLP marking |
| HTTP cookie | CsrfToken + NSC_TASS | Beazley Security Labs [33]; IFIN [40] | Cookies used to access the .ctxs.receiver webshell (GreyNoise, via Beazley) | NetScaler uses both cookies legitimately. Suspicious only when NSC_TASS carries URL-encoded commands on requests to the webshell path. | Public advisory, no TLP marking |
| Log string | pitboss log lines containing IFS or b64decode | Beazley Security Labs [33] | Log-poisoning exploitation of CVE-2026-88771 (Beaumont, via Beazley); check ns.log, /var/log/messages and your SIEM | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. | Public advisory, no TLP marking |
| Log string | "missed too many heartbeats" or "unexpectedly died" in authentication log lines | Beazley Security Labs [33]; CERT-EU [19] | Crafted login usernames imitating packet-engine messages (watchTowr, CERT-EU, via Beazley); ns.log | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. | Public advisory, no TLP marking |
| User-Agent | ns-88771-poc | Beazley Security Labs [33] | Public PoC/scanner User-Agent seen by Lupovis (via Beazley); Apache access logs | A public testing tool, not an actor indicator. Means someone tested the box. | Public advisory, no TLP marking |
| String | NX-CVE-OK | Beazley Security Labs [33] | Test-marker text dropped in web folders by exploitation checks (Lupovis, via Beazley); grep /netscaler/ns_gui | Means the box was reached and is exploitable, not necessarily backdoored. | Public advisory, no TLP marking |
| File permission | /bin/sh expected -r-xr-xr-x (setuid means modified) | Beazley Security Labs [33]; Google GTIG / Mandiant [25] | Check with ls -l /bin/sh before patching; the installer sets setuid (Beazley, GTIG) | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. | Public advisory, no TLP marking |
| IPv4 | 172.247.44.85 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CNSERVERS LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 165.227.201.112 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 173.231.39.244 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (WebNX, Inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 64.225.103.14 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, Germany) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 159.65.104.231 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 142.93.205.229 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 182.101.54.57 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 87.224.84.82 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Spitfire Network Services Limited, United Kingdom) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 137.220.53.135 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (The Constant Company, LLC, Canada) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 120.28.233.211 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Globe Telecoms, Philippines) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 149.28.58.71 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (The Constant Company, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 23.234.111.22 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (tzulo, inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 198.13.159.233 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (BL Networks, Netherlands) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 85.221.203.85 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (INEA sp. z o.o., Poland) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 46.150.68.55 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Kyivski Telekomunikatsiyni Merezhi, Ukraine) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 159.26.103.184 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Proton AG, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 45.249.89.172 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (SpeedyPage Ltd, Japan) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 197.52.9.138 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (TE-AS, Egypt) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 180.242.113.168 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (PT Telekomunikasi Indonesia, Indonesia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 85.117.117.248 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Mobile Telecom-Service LLP, Kazakhstan) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 73.43.85.7 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Comcast Cable Communications, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 88.180.103.22 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Free SAS, France) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 194.28.195.90 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Dialog-K LLC, Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 95.63.246.50 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Vodafone Espana S.A.U., Spain) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 31.13.192.160 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (SKAT POPOVO Ltd., Bulgaria) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 185.170.55.89 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (LLC Electron-Telecom, Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 104.203.50.26 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Blue Stream, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 37.19.221.171 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Datacamp Limited, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 45.143.167.96 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (BlueVPS OU, Netherlands) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 206.232.71.215 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Leaseweb Deutschland GmbH, Germany) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 130.94.106.141 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (LIGHT NODE LIMITED, Argentina) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 58.187.56.89 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (FPT Telecom Company, Vietnam) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 171.106.10.118 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 82.24.212.15 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Shock Hosting LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 178.66.43.241 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (PJSC Rostelecom, Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 185.209.15.246 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (ESTOXY OU, Netherlands) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 94.190.77.195 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (INTERRA telecommunications group, Ltd., Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 93.177.60.233 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (PJSC Rostelecom, Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 68.46.140.222 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Comcast Cable Communications, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 178.218.40.232 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (ATEXS PLUS Ltd., Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 49.36.107.103 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Reliance Jio Infocomm Limited, India) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 191.37.30.194 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (WRNET LTDA, Brazil) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 23.234.74.48 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (tzulo, inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 72.73.231.73 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Verizon Business, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 95.229.84.239 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Telecom Italia S.p.A., Italy) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 113.137.102.68 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.243.125.255 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.76.92.109 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 8.217.173.25 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 8.210.67.91 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.239.205.29 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.76.132.65 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 8.218.219.56 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.76.102.1 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.76.63.52 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 8.210.119.74 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 64.177.93.71 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (The Constant Company, LLC, Mexico) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 44.252.255.141 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Amazon.com, Inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 194.242.130.193 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (WAHYU, Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 125.122.56.47 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 23.132.164.35 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Netiface America, Inc., Switzerland) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 92.118.204.229 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Catixs Ltd, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 54.70.59.128 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Amazon.com, Inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 44.226.128.41 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Amazon.com, Inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 4.246.63.96 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Microsoft Corporation, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 176.65.148.54 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Pfcloud UG, Netherlands) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 104.28.193.147 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 29 (Cloudflare, Inc., Japan) | Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 104.28.211.105 | GreyNoise tag [39] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 29 (Cloudflare, Inc., Japan) | Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs. | GreyNoise Visualizer tag search, viewed Sep 29 |
| User-Agent | Python-urllib | Lupovis (@LupovisDefence) on X, Sep 28 [43] | Client used for CVE-2026-88771 log-poison exploitation on Lupovis decoys (payload runs id;uname, DNS callback to httpworkbench) | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. Python-urllib is a common library default; only meaningful together with the auth-endpoint payload. | Public post, no TLP marking |
| URI path | /vpn/scripts/linux/nsgclient18.deb | Maurice_Sec on X [72]; CyberMaxx [35]; Google GTIG / Mandiant [25] | GET requests referenced in a NetScaler Console IoC scanner finding (Maurice_Sec field notes) | Single practitioner report; the author is "not 100%" on this finding. Matches the GTIG nsgclient*.deb staging pattern. A legitimate client package normally lives at similar paths, so check file content, not just the name. | Public post, no TLP marking |
| URI path | /vpn/scripts/linux/nsgclient18_32.deb | Maurice_Sec on X [72]; CyberMaxx [35]; Google GTIG / Mandiant [25] | GET requests referenced in a NetScaler Console IoC scanner finding (Maurice_Sec field notes) | Single practitioner report; the author is "not 100%" on this finding. Matches the GTIG nsgclient*.deb staging pattern. Check file content, not just the name. | Public post, no TLP marking |
| Domain | echvista.com | IFIN [40] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. No A record when checked on Sep 29. | Public, no restriction |
Post-exploitation steps attempted on a GreyNoise sensor
GreyNoise says the attacker did not gain a foothold on its sensor. The steps below show the attacker's playbook, not a successful compromise.
- Set setuid and setgid on
/bin/sh. - Planted a PHP webshell that authenticates by cookie.
- Killed and restarted httpd, for anti-forensics or to activate the changed config.
A Reddit user described one sample of the .ctxs.receiver file, and IFIN relayed the description. This is unconfirmed. [40]
- The file is a 237-byte PHP one-liner.
- It runs a URL-decoded cookie value through
passthru(), but only when a second cookie matches a hardcoded 16-character hex token. - NetScaler uses both cookie names legitimately, so the traffic blends in.
- The file survived a reboot and the upgrade to 14.1-73.37.
The token likely differs per victim, so search the file's content rather than relying on its hash.
Source: GreyNoise, "Swarming Against Citrix 0-Day Exploitation". Victim-specific names and IPs from later IR-vendor writeups are deliberately left out. Beaumont warns that publishing them exposes organisations that have not yet remediated. [51]
Detection and hunting for NetScaler compromise
In short: review httpd.conf for PHP handler and AliasMatch changes, look for PHP files in VPN script and media directories, check /bin/sh for setuid, and correlate DTLSv1.0 handshake failures with NSPPE crashes. Sources: GTIG/Mandiant, CERT-EU and GreyNoise, as of 30 September 2026. [25][19]
A clean scan does not clear a host. A checker can miss a planted webshell, especially when logs have rotated or permissions were changed.
CERT-EU hunting patterns Passive
- base64 strings in the
User-Agentheader that start withINDEX:. PPE missed too many heartbeatsentries in authentication logs.- Check that
httpd.confis intact, for example by looking for the AliasMatch in the IoC table.
Source: CERT-EU writeup
CIRCL TR-100 Config check
For each CVE, CIRCL gives CLI commands that check whether your appliance's configuration exposes it. Run them on appliances you administer.
Source: CIRCL TR-100
Citrix Console IoC checker Limits per Beaumont Validated
- Available only through support or under NDA. [45]
- Incomplete: it does not check for suid on
/bin/sh. [48] - Citrix's own documentation says the IoC information "might be of limited forensic value and might fail to identify actual compromises", and advises retaining experienced forensic investigators. [4]
- In the field, the Console scanner has flagged base64 content referencing the
.ctxs.receiverwebshell, "Certificate digest verification failed" (possibly tampered certificate or key files) and "Binary Fingerprinting detected", according to one practitioner's notes. [72] - Misses earlier semi-successful attempts once logs have rotated. [46]
The missing suid check and the log-rotation gap were validated independently on 29 September. The NDA point has not been verified.
Beaumont also says Some really big orgs are backdoored after patching still
. That claim is not independently verified. He has asked national CSIRTs (NCSCs) to publish a detection script. [48]
GTIG/Mandiant artefacts and YARA Passive
Successful CVE-2026-88772 exploitation left two log artefacts:
- In syslog, an
SSL_HANDSHAKE_FAILUREwithClientVersion DTLSv1.0andReason "Handshake failure-Internal Error". - In
/var/log/messages, an NSPPE termination logged bypitboss, the watchdog daemon that restarts crashed processes.
Also look for httpd.conf changes that make the web server treat other file types as PHP, such as AddHandler application/x-httpd-php .deb.
GTIG publishes five YARA rules: G_APT_Backdoorwebshell_WHIPSHOT_1, G_APT_Tunneler_SLAPSHOT_1, G_Hunting_Backdoorwebshell_NetScaler_C2Headers_1, G_Hunting_Config_NetScaler_PHP_1 and G_Hunting_Script_NetScaler_Persistence_1. This page links to them rather than copying them.
Source: GTIG/Mandiant advisory
Nextron THOR Scanner rules
As of 29 September, Nextron has three rules in the THOR Preview channel:
LOG_SUSP_EXPL_CVE_2026_88771_Sep26WEBSHELL_CSS_PassThrough_Sep26, which detects the webshell's behaviour, not only its filenameEXPL_CVE_2026_88772_POC_Sep26, which detects PoC artefacts, not attacks on an appliance
Nextron also published a YAML filesystem IoC set derived from Citrix's scanner script. It covers 12 of the script's checks, consolidated into four file rules. It leaves out the 22 checks that depend on logs, configuration or runtime state.
Preview-channel rules have not finished manual QA, so expect more false positives than with stable rules. A match is a lead for investigation, not proof of compromise.
Source: Nextron Systems
Community detection rules Rules
- Elastic: "Potential NetScaler Log Poisoning Command Injection Attempt", an EQL rule on Citrix ADC logs. Merged on 28 September.
- Sigma pull request #6352: shell metacharacters sent to the NetScaler authentication endpoint. Not yet merged.
- Corelight: Zeek hunting queries, including a search for the reverse-shell IP in the IoC table.
- Nuclei pull request #17336: an active injection probe, not a version check. It writes to the target's logs, so run it only on systems you own or administer. Not yet merged.
- Lupovis suggests two hunts:
POST /nf/auth/doAuthentication.dorequests whose body containspitboss PPE unexpectedly died NSPPE, and DNS lookups from a NetScaler ending ininstances.httpworkbench.com. [65]
Beazley Security Labs checks Passive
Beazley's BSL-A1216 advisory lists read-only shell checks. It splits them into those to run before patching (the web-server config, /bin/sh permissions and NX-CVE-OK test markers, which a reboot rebuilds) and those that persist across upgrades (hidden files under /var/netscaler/logon). It also recommends comparing /etc/httpd.conf with a clean appliance on the same build.
Source: Beazley Security Labs BSL-A1216
watchTowr Detection Artefact Generators Active tests
These tools send traffic to an appliance. Run them only against systems you own or administer. This page links to the repositories. It does not reproduce their code or payloads.
- CVE-2026-88771: watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771. This is the only PoC-class tool Beaumont vouches for. That was validated independently on 29 September, though the post itself has not been found.
- CVE-2026-88772: watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772. It sends 120 DTLS records (about 176,640 bytes) to the gateway and measures the response.
Beaumont describes the other GitHub "PoCs" he has seen as fake AI slop. That is his characterisation. [52]
Remediation: patching NetScaler ADC and Gateway
In short: check for compromise and preserve evidence first, then upgrade to 14.1-73.37 or 13.1-64.23 or later (FIPS/NDcPP builds below), per Citrix CTX697096 as of 30 September 2026. Patching does not remove an existing backdoor. [1]
Fixed builds (Citrix CTX697096)
| Fixed build, exactly as listed by Citrix |
|---|
| NetScaler ADC/Gateway 14.1-73.37 and later |
| NetScaler ADC/Gateway 13.1-64.23 and later |
| NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later |
Source: Citrix CTX697096. Use the bulletin as the authority for which build applies to your deployment.
13.1 upgrades: watchTowr advises running show ns variable first. If it returns any variables, use 13.1-64.24 to avoid a known reboot loop during the upgrade. [61] CVE-2026-88778 is fixed by enabling Enhanced ISN Generation, not by the upgrade alone. [13]
End-of-life releases: NetScaler ADC and Gateway 12.1 and 13.0 are end of life, receive no fix and are likely vulnerable. Migrate them to a supported release. [15][41]
The bulletin is inconsistent about the last build. Its fixed-builds list says 13.1.37.279, while its affected-versions list says "FIPS and NDcPP BEFORE 13.1-37.279". Truesec and IFIN use 13.1-37.279. The table above keeps Citrix's fixed-builds wording exactly.
After patching
- Check for compromise and preserve evidence before you patch. Mandiant's CTO, Charles Carmakal, says customers should examine their systems
for compromise *before* upgrading/patching
. [62] Unit 42 lists the evidence to capture: [63]- a NetScaler VPX instance snapshot
- logs on remote syslog servers and in NetScaler Console
- a technical support bundle
- a packet engine core dump
- Patch to a fixed build from the table above.
- Hunt for compromise. Check for:
- webshells, including the GreyNoise path and alias above
- changes to
httpd.conf, such as an unexpected AliasMatch - unusual permissions on
/bin/sh, such as setuid or setgid
- Assume activity may be weeks old. Beaumont says slow disclosure means attackers have been active for weeks. [46]
Patching closes the vulnerabilities. It does not reverse a compromise that already happened. This page does not give remediation commands or guarantees. Follow Citrix and your national CSIRT.
NetScaler zero-day FAQ
What is PitScaler?
PitScaler is the name Kevin Beaumont gave on 28 Sep 2026 to the exploitation of Citrix NetScaler ADC and NetScaler Gateway zero-days CVE-2026-88771 and CVE-2026-88772. Citrix disclosed them, with six other CVEs, in bulletin CTX697096 on 27 Sep 2026. [47][1]
Which NetScaler vulnerabilities are exploited?
CVE-2026-88771 (unauthenticated remote command execution in the default configuration, CVSS 4.0 9.5) and CVE-2026-88772 (DTLS memory overflow leading to RCE or DoS, CVSS 4.0 9.5). CISA added both to its KEV catalog on 27 Sep 2026 with a 30 Sep deadline. No exploitation is reported for the other six CVEs in CTX697096. [1][12]
Which NetScaler versions fix CVE-2026-88771 and CVE-2026-88772?
Per CTX697096: NetScaler ADC/Gateway 14.1-73.37 and later; 13.1-64.23 and later; ADC 14.1-FIPS 14.1-73.37 FIPS and later; ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later (the bulletin also writes this build as 13.1-37.279). [1]
Does patching remove a NetScaler backdoor?
No. Patching closes the vulnerabilities but does not remove webshells or configuration changes planted before the update. Check for compromise and preserve evidence (logs, memory, a VM snapshot) before patching, then patch. [45][25][19]
How do I check a NetScaler for compromise?
Look for AddHandler or AliasMatch changes in httpd.conf that make non-PHP files run as PHP; PHP code in VPN script and media directories such as /var/netscaler/gui/vpn/scripts/linux/; a setuid bit on /bin/sh; /tmp/.uxdport and /tmp/.uxdlock (SLAPSHOT); and DTLSv1.0 SSL_HANDSHAKE_FAILURE log entries followed by an NSPPE crash. Beaumont reports that the Citrix checker misses the /bin/sh setuid check, so a clean scan does not clear a host. [25][19][36][48]
When did the exploitation start?
eSentire saw CVE-2026-88771 exploited as early as 5 Sep 2026, more than three weeks before disclosure, and Google GTIG and Mandiant report CVE-2026-88772 exploitation since at least early September. Australia's ACSC advises reviewing for compromise since at least 4 Sep 2026. GreyNoise recorded a CVE-2026-88771 attempt on 24 Sep 2026. [32][25][11][36]
Who is behind the attacks?
No vendor has publicly attributed the activity to a named threat actor as of 30 Sep 2026. Kevin Beaumont calls the attackers probably nation-state aligned; that is his assessment, not a confirmed attribution. [27][44]
Should I shut down or disconnect my NetScaler?
Before patches existed, many organisations were advised to shut down or disconnect NetScaler appliances: the Dutch central government applied "disconnect unless" from 26 Sep 2026, and Danish agencies including PET, the Armed Forces and the police switched theirs off. Now that fixed builds exist, GTIG/Mandiant recommend upgrading, isolating only appliances with confirmed or suspected compromise, and, if patching is delayed, disabling DTLS or blocking inbound UDP/443 upstream (this mitigates CVE-2026-88772 only, not CVE-2026-88771). [17][66][55][25]
Were CVE-2026-88771 and CVE-2026-88772 exploited as zero-days?
Yes. Citrix confirmed exploitation on unmitigated appliances when it disclosed them on 27 Sep 2026. eSentire saw CVE-2026-88771 exploited from 5 Sep, and GreyNoise recorded an attempt on 24 Sep, before any patch or CVE was public. [1][32][36]
Who found the NetScaler zero-days?
The exploited flaws were found during incident response: BleepingComputer reports Citrix discovered them while investigating incidents at customers, and watchTowr says they were discovered during forensics. The CTX697096 bulletin credits Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov, without saying which CVE each reported. [55][34][1]
Is PitScaler a live incident feed?
No. PitScaler is an independent historical snapshot as of 30 September 2026, morning CEST. Check official advisories such as Citrix CTX697096 and the CISA alert for current status. [1][5]
How many NetScaler appliances are exposed?
Censys counted 42,735 NetScaler hosts on 28 Sep 2026, Unit 42 counted 50,277 potentially vulnerable exposed instances on 27 Sep, and Shadowserver reports more than 20,000 instances exposed and potentially at risk. These are exposure counts, not confirmed compromises. [41][63][64]
References
Bracketed numbers in the text, such as [1], point to the rows below. Every link below is the exact URL from the compiled dataset. IFIN, Truesec, GTIG/Mandiant, Nextron, The Register, Unit 42, the Dutch government letter, two more Beaumont posts, the CVE record, a second BleepingComputer article, the Canada, HKCERT and ACSC advisories, eSentire, Beazley Security Labs, Ingeniøren, DKCERT, NHS England, the CERT-EU advisory, SDxCentral, heise, Dark Reading, Lupovis's own post, and the Censys, Shadowserver, Lupovis, Beazley, Corelight, Elastic, Sigma and Nuclei material were added later, on 29 September. Links marked verification pending did not load in an automated check at build time. The URL has been kept unchanged, not replaced. For all other links, the check only showed that the page loaded, not that its content was reviewed.
| # | Source | Type | URL |
|---|---|---|---|
| 1 | Citrix - CTX697096 security bulletin (Sep 27) | Primary official advisories | https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html |
| 2 | Citrix community blog - Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (incl. IoC section) verification pending | Primary official advisories | https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/ |
| 3 | Citrix (CTX-Michael) on r/Citrix, Sep 27 - CRITICAL UPDATE announcement | Primary official advisories | https://www.reddit.com/r/Citrix/comments/1wro1yf/critical_update_citrix_netscaler_adc_and_citrix/ |
| 4 | NetScaler Console documentation - Indicators of Compromise detection (incl. Citrix disclaimer on limits) | Primary official advisories | https://docs.netscaler.com/en-us/netscaler-console-service/instance-advisory/ioc |
| 5 | CISA alert - Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC/Gateway (Sep 27) | Primary official advisories | https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway |
| 6 | NCSC-NL advisory NCSC-2026-0394 (probability high, damage high; per-CVE scores and preconditions) | Primary official advisories | https://advisories.ncsc.nl/ |
| 7 | NCSC-UK - Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Gateway | Primary official advisories | https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway |
| 8 | CSA Singapore - AL-2026-129 | Primary official advisories | https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-129/ |
| 9 | Canadian Centre for Cyber Security - AL26-024 | Primary official advisories | https://www.cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772 |
| 10 | HKCERT - Citrix Products Multiple Vulnerabilities (Sep 28) | Primary official advisories | https://www.hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928 |
| 11 | ACSC (Australia) - Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway | Primary official advisories | https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products |
| 12 | CISA Known Exploited Vulnerabilities catalog (both CVEs added Sep 27, due Sep 30) | Primary official advisories | https://www.cisa.gov/known-exploited-vulnerabilities-catalog |
| 13 | CERT-EU Security Advisory 2026-014 - Critical Vulnerabilities in Citrix NetScaler ADC and Gateway (Sep 27) | Primary official advisories | https://cert.europa.eu/publications/security-advisories/2026-014/ |
| 14 | DKCERT (CERT for Danish universities and research) - To kritiske NetScaler 0-dage udnyttes aktivt før patch (Sep 29) | Primary official advisories | https://cert.dk/node/639 |
| 15 | NHS England Digital cyber alert CC-4858 (Sep 28) - Exploitation of zero-day vulnerabilities affecting Citrix NetScaler | Primary official advisories | https://digital.nhs.uk/cyber-alerts/2026/cc-4858 |
| 16 | CIRCL TR-100 - per-CVE configuration-check CLI commands | Primary official advisories | https://www.circl.lu/pub/tr-100/ |
| 17 | Dutch government letter to parliament - Kwetsbaarheden Citrix Netscaler (2026D47262, Sep 29) | Primary official advisories | https://www.tweedekamer.nl/kamerstukken/brieven_regering/detail?id=2026D47262&did=2026D47262 |
| 18 | CVE.org - CVE-2026-88771 record (reserved Sep 10 07:14 UTC by NetScaler; published Sep 27 16:02 UTC) | Primary official advisories | https://www.cve.org/CVERecord?id=CVE-2026-88771 |
| 19 | CERT-EU - Taking "execute logging" a bit too literally - CVE-2026-88771 (Sep 28) | Technical research | https://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771 |
| 20 | watchTowr Labs part 1 - Oh Look, the Foot Gun Went Off Again (CVE-2026-88771) (Sep 28) | Technical research | https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/ |
| 21 | watchTowr Detection Artefact Generator - CVE-2026-88771 (GitHub) | Technical research | https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771 |
| 22 | watchTowr Labs part 2 - Here We Go Again (CVE-2026-88772), Sina Kheirkhah (Sep 29) | Technical research | https://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/ |
| 23 | watchTowr Detection Artefact Generator - CVE-2026-88772 (GitHub) | Technical research | https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772 |
| 24 | Truesec - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (Sep 28) | Technical research | https://www.truesec.com/hub/blog/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway |
| 25 | Google GTIG / Mandiant - Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances (Sep 29) | Technical research | https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances |
| 26 | Nextron Systems (Florian Roth) - New THOR Detection Coverage for CVE-2026-88771 and CVE-2026-88772 (Sep 29) | Technical research | https://www.nextron-systems.com/2026/09/29/new-thor-detection-coverage-for-citrix-netscaler-cve-2026-88771-and-cve-2026-88772/ |
| 27 | Beazley Security advisory (updated Sep 29) - IoC table incl. Lupovis honeypot IPs | Technical research | https://beazley.security/alerts-advisories/critical-vulnerability-in-citrix-netscaler-zero-day-prompts-emergency-shutdowns-cve-2026-88771-cve-2026-88772 |
| 28 | Corelight - Hunting Citrix NetScaler zero-days (Zeek queries, Sep 28) | Technical research | https://corelight.com/blog/hunting-citrix-netscaler-zero-days-corelight |
| 29 | Elastic detection rule - Potential NetScaler Log Poisoning Command Injection Attempt (merged Sep 28) | Technical research | https://github.com/elastic/detection-rules/blob/main/rules/network/initial_access_netscaler_log_poisoning_command_injection.toml |
| 30 | SigmaHQ pull request #6352 - NetScaler auth endpoint shell metacharacters (open, Sep 29) | Technical research | https://github.com/SigmaHQ/sigma/pull/6352 |
| 31 | Nuclei templates pull request #17336 - CVE-2026-88771 active probe (open, Sep 28) | Technical research | https://github.com/projectdiscovery/nuclei-templates/pull/17336 |
| 32 | eSentire TRU - Update: ongoing exploitation of NetScaler CVE-2026-88771 / -88772 (first-hand IR, Sep 29) | Technical research | https://www.esentire.com/security-advisories/update-ongoing-exploitation-of-citrix-netscaler-adc-and-netscaler-gateway-vulnerabilities-cve-2026-88771-cve-2026-88772 |
| 33 | Beazley Security Labs - BSL-A1216 advisory (updates 3-4, Sep 29): consolidated IoCs and hunting commands | Technical research | https://labs.beazley.security/advisories/BSL-A1216 |
| 34 | watchTowr (@watchtowrcyber) on X, Sep 26 - "Unpatched, 0days. Exploited in-the-wild - discovered during forensics." | Technical research | https://x.com/watchtowrcyber/status/2103972792043479307 |
| 35 | CyberMaxx - Patches required: Citrix NetScaler vulns exploited in the wild (IoC notes) | Technical research | https://www.cybermaxx.com/resources/patches-required-citrix-netscaler-vulns-exploited-in-the-wild-cve-2026-88771-and-cve-2026-88772/ |
| 36 | GreyNoise - Swarming Against Citrix 0-Day Exploitation (TLP:CLEAR IoCs, Sep 28) | Telemetry and IoCs | https://greynoise.io/blog/swarming-against-citrix-0-day-exploitation |
| 37 | GreyNoise Chronicle - GNTL-20260928 CVE-2026-88771 timeline | Telemetry and IoCs | https://www.greynoise.io/chronicle/gntl-20260928-citrix-cve-2026-88771 |
| 38 | GreyNoise Visualizer - IP 149.104.78.141 | Telemetry and IoCs | https://viz.greynoise.io/ip/149.104.78.141 |
| 39 | GreyNoise tag - Citrix NetScaler CVE-2026-88771 Login Command Injection RCE Attempt | Telemetry and IoCs | https://viz.greynoise.io/tag/citrix-netscaler-cve-2026-88771-login-command-injection-rce-attempt |
| 40 | IFIN - Multiple Citrix Netscaler 0-Days Exploited (tracking thread, from Sep 26; observables "shared without restriction") | Telemetry and IoCs | https://ifin.network/t/multiple-citrix-netscaler-0-days-exploited/867 |
| 41 | Censys advisory - NetScaler exposure (42,735 hosts, Sep 28) | Telemetry and IoCs | https://censys.com/advisory/cve-2026-10747-2/ |
| 42 | Defused (@DefusedCyber) on X, Sep 29 - decoy hits across multiple CVE-2026-88771 paths | Telemetry and IoCs | https://x.com/DefusedCyber/status/2104888497693708505 |
| 43 | Lupovis (@LupovisDefence) on X, Sep 28 - decoys catch CVE-2026-88771 exploitation hours after the PoC | Telemetry and IoCs | https://x.com/lupovisdefence/status/2104595071362326680 |
| 44 | Beaumont, Sep 27 - chained CVEs, webshells all September, "Probably nation state aligned" | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117343729453093307 |
| 45 | Beaumont, Sep 27 - patches live; detection script behind NDA; patching does not remove backdoors | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117343821114841048 |
| 46 | Beaumont, Sep 27 - Console check misses attempts when logs have rotated | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117345540231975640 |
| 47 | Beaumont, Sep 28 22:49 UTC - names "PitScaler", >100 victim orgs (his claim) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117351107654208046 |
| 48 | Beaumont, Sep 28 23:02 UTC - Citrix checker incomplete (suid /bin/sh) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117351155381900219 |
| 49 | Beaumont, Sep 29 04:39 UTC - mass exploitation, <10% patched (his claim) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117352481501981552 |
| 50 | Beaumont, Sep 29 06:18 UTC - public message to the NSA (his unverified claim) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117352869498139711 |
| 51 | Beaumont, Sep 29 16:12 UTC - IR vendors publishing victim-unique webshell names | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117355208096613386 |
| 52 | Beaumont, Sep 28 15:13 UTC - GitHub "PoCs" for the new Citrix vulns are "fake AI slop" | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117349313638958333 |
| 53 | Beaumont, Sep 29 18:32 UTC - Dutch government shuts down all Citrix NetScalers (relaying @bert_hubert) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117355758746619146 |
| 54 | BleepingComputer (Sep 29) - Hackers exploit Citrix NetScaler zero-day to deploy web shells | Press and vendor coverage | https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/ |
| 55 | BleepingComputer (Sep 27) - Citrix admins warned to shut down NetScalers | Press and vendor coverage | https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/ |
| 56 | SecurityWeek (Sep 28) - Citrix confirms 2 NetScaler zero-days | Press and vendor coverage | https://www.securityweek.com/citrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug/ |
| 57 | The Record (Sep 28) - US, UK warn of Citrix NetScaler zero-day bug | Press and vendor coverage | https://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug |
| 58 | CyberScoop (Sep 28) - delayed-disclosure angle | Press and vendor coverage | https://cyberscoop.com/citrix-zero-days-delayed-disclosure/ |
| 59 | Sophos CTU (Sep 28) - CVE-2026-88771 / -88772 in active exploitation | Press and vendor coverage | https://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation |
| 60 | Rapid7 ETR (Sep 28) | Press and vendor coverage | https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/ |
| 61 | watchTowr FAQ (Sep 27-28) | Press and vendor coverage | https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/ |
| 62 | The Register (Sep 29) - Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services | Press and vendor coverage | https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867 |
| 63 | Unit 42 (Palo Alto Networks) - NetScaler zero-days threat brief (Sep 27, updated Sep 28) | Press and vendor coverage | https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/ |
| 64 | Cybersecurity Dive (Sep 28) - Shadowserver: more than 20,000 instances exposed | Press and vendor coverage | https://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/ |
| 65 | Help Net Security (Sep 29) - NetScaler zero-day exploitation escalates into mass attacks (Lupovis, Censys) | Press and vendor coverage | https://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/ |
| 66 | Ingeniøren (Sep 30) - Alvorlige huller i kendt software: PET, Forsvaret og Politiet hastelukker systemer | Press and vendor coverage | https://ing.dk/artikel/alvorlige-huller-i-kendt-software-pet-forsvaret-og-politiet-hastelukker-systemer |
| 67 | SDxCentral (Sep 29) - NetScaler bugs bring critical sectors down in Europe (citing Techzine) | Press and vendor coverage | https://www.sdxcentral.com/news/netscaler-bugs-bring-critical-sectors-down-in-europe/ |
| 68 | Cybersecurity Dive (Sep 29) - Citrix NetScaler exploitation began days before public notification | Press and vendor coverage | https://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/ |
| 69 | heise online (Sep 27) - New zero-day exploits in Citrix NetScaler | Press and vendor coverage | https://www.heise.de/en/news/Security-researchers-warn-New-zero-day-exploits-in-Citrix-Netscaler-11467269.html |
| 70 | Dark Reading (Sep 29) - Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers | Press and vendor coverage | https://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix |
| 71 | Omroep Brabant (Sep 27) - Storing bij ziekenhuizen door kritieke kwetsbaarheden in systeem (Amphia, ETZ, Z-CERT) | Press and vendor coverage | https://www.omroepbrabant.nl/nieuws/6028828/storing-bij-ziekenhuizen-door-kritieke-kwetsbaarheden-in-systeem |
| 72 | Maurice_Sec on X - notes from the field on NetScaler Console IoC scanner findings | Community | https://x.com/Maurice_Sec/status/2104541998858240487 |
| 73 | r/Citrix - "Netscaler leak?" thread (~Sep 26) | Community | https://www.reddit.com/r/Citrix/comments/1wqjk9a/netscaler_leak/ |