Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data.
LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler authentication events containing attacker-controlled usernames designed to weaponize CVE-2026-88771.
CVE-2026-88771 (CVSS score: 9.5) is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
The security flaw, along with CVE-2026-88772, was disclosed last week after reports that the Dutch National Cyber Security Centre (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands that urged organizations to shut their appliances down, citing active exploitation. As of writing, there are currently no details about who is behind these efforts.
"One of the most consistent characteristics across the identified events was attacker-controlled authentication data containing variations of the pitboss and NSPPE strings associated with exploitation of CVE-2026-88771," LevelBlue said.
Other attempts have been observed using curl or wget to fetch additional payloads from external servers, or extract NetScaler configuration data -
- 64.94.85[.]67:443/update_c08937.pl
- 31.56.197[.]72:9090/lula
- 23.27.143[.]20:9000/main.py
"Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation," LevelBlue said. "The attempts included payload retrieval and execution as well as collection and staging of NetScaler configuration data."
Notable among the second-stage payloads is a Python script ("main.py") that's designed to establish a reverse shell to "45.141.21[.]130" over TCP port 443. It also searches for running processes associated with "/var/python/bin/customsnmpd" and forcefully terminates them by issuing a "kill -9" command.
Another second-stage payload, "update_c08937.pl," is a Perl script with several post-exploitation capabilities -
- Modify "/flash/nsconfig/ns.conf" to create a local account named sec_monitor and assign it the superuser role.
- Archive the "/flash/nsconfig" directory into "/tmp/update_result_3567cs.tgz" and upload the resulting archive containing NetScaler configuration data to "64.94.85[.]67:443." The script then deletes the archive and erases itself to reduce the forensic footprint on disk.
- Change the permissions of "/bin/sh" to 6555 and deploy a PHP web shell at "/var/netscaler/logon/LogonPoint/.local_journal" for remote command execution and file upload and download.
- Modify "/etc/httpd.conf" to enable PHP execution and map the web shell to URLs resembling legitimate NetScaler CSS resources, corroborating activity observed by GreyNoise.
"While some attempts used commands such as whoami to test command execution, others attempted to retrieve additional payloads, collect NetScaler configuration data, establish reverse shells, create privileged accounts, and deploy web shells," LevelBlue said.
The disclosure comes a day after Mandiant Consulting and Google Threat Intelligence Group (GTIG) said dozens of organizations have been impacted by attacks exploiting CVE-2026-88772 to deliver PHP web shells, like WHIPSHOT, and a Python tunneler dubbed SLAPSHOT.
Update
In a follow-up report published on October 6, 2026, eSentire said it observed multiple threat actors exploiting CVE-2026-88771 both before and after public disclosure to deploy PHP-based web shells, modify Apache configuration files to enable their execution, and obtain root-level shell access.
"Pre-disclosure activity involved a lightweight PHP web shell, while Platypus was used for remote management," eSentire said. "Other activity relied on a Perl-based installer that deployed a PHP web shell and created a backdoor account in NetScaler, along with a Python-based reverse shell."
At least four different clusters of activity have been detected against its customers -
- Cluster A, a pre-disclosure campaign which deployed web shells in the "/var/netscaler/gui/vpn/scripts/linux/" directory. The web shell is disguised as a ".deb" file and is nearly identical to the "lightweight installer web shell" family put to use in attacks exploiting CVE-2026-88772.
- Cluster B, a post-disclosure campaign which targeted three customers on September 28, 2026, and delivered the Platypus remote management tool by means of a shell script stager for follow-on activity. The Golang tool has also been put to use by China-nexus threat actors to manage victim devices that are part of the JDY botnet.
- Cluster C, a post-disclosure campaign which targeted four customers on September 29, 2026, and exploited CVE-2026-88771 via watchTowr's proof-of-concept (PoC) to deliver "update_c08937.pl," the same Perl script detailed by LevelBlue. It's also designed to drop a PHP-based web shell (".local_journal") that allows logged-in attackers to upload and download files, and execute arbitrary commands.
- Cluster D, a post-disclosure campaign which targeted a single customer on September 29, 2026, and leveraged watchTowr's PoC to drop a Python-based reverse shell.
"Exploitation was observed before and after public disclosure, with some post-disclosure activity occurring within roughly 24 hours, highlighting how quickly threat actors target internet-facing appliances once vulnerability details or proof-of-concept code becomes public," eSentire said.
(The story was updated after publication on October 6, 2026, with additional insights from eSentire.)




