Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: Active Exploitation Hunt

Threat Overview

Citrix published bulletin CTX697096 on September 27, 2026 and confirmed exploitation of two critical NetScaler zero-days. CVE-2026-88771 is a CVSS 9.5 unauthenticated command-execution flaw affecting every customer-managed NetScaler ADC and NetScaler Gateway deployment, including default configurations. CVE-2026-88772 is a CVSS 9.5 memory-overflow flaw capable of remote code execution or denial of service when DTLS is enabled; DTLS is enabled by default on VPN virtual servers. Fixed builds are 14.1-73.37, 13.1-64.23, 14.1-FIPS 14.1-73.37, and 13.1-FIPS/NDcPP 13.1.37.279 or later. On September 29, Google Threat Intelligence Group and Mandiant published observed exploitation details for CVE-2026-88772. The actor used malformed or fragmented DTLS records over UDP/443 to crash the NetScaler Packet Processing Engine and obtain initial root access. Post-exploitation activity included modified Apache handlers, .deb and .sig PHP web shells, icon-to-web-shell aliasing, setting the SUID bit on /bin/sh, appliance or HTTP-service restarts, WHIPSHOT web-shell tunneling, and the SLAPSHOT Python proxy for internal reconnaissance and credential theft. This is a material technical update to the earlier pre-advisory NetScaler warning because fixed builds, CVE identifiers, confirmed exploitation mechanics, IOCs, and post-exploitation artifacts are now available.

References

Impacted Systems

  • Vendor/product: Customer-managed Citrix NetScaler ADC and NetScaler Gateway, including hardware and VPX deployments.
  • CVE-2026-88771: All deployments; default configuration is affected and no additional feature is required.
  • CVE-2026-88772: Deployments with DTLS enabled; enabled by default on VPN virtual servers and applicable to DTLS virtual servers.
  • Affected versions: All supported 14.1 and 13.1 builds below the fixed versions; Citrix ADC/NetScaler 12.1 and 13.0 are end of life and must be moved to a supported fixed release.
  • Fixed versions: 14.1-73.37+, 13.1-64.23+, 14.1-FIPS 14.1-73.37+, and 13.1-FIPS/NDcPP 13.1.37.279+.
  • Platform/service role: Internet-facing ADC, VPN gateway, authentication gateway, or application-delivery edge appliance; CVE-2026-88772 exploitation observed over UDP/443.
  • Deployment model: Customer-managed appliances are in scope. Citrix-managed cloud services are not claimed affected by this customer-managed appliance bulletin.

Why this matters

NetScaler appliances terminate authentication and application traffic at the enterprise edge, often lack EDR coverage, and can reach identity and internal systems. The observed campaign achieved root access, installed stealth web shells and a tunnel, and used the appliance for internal reconnaissance and credential theft. Patching does not remove persistence already installed before the update.

Exploitation Status

Citrix confirms exploitation of both CVEs on unmitigated deployments. GTIG/Mandiant directly observed CVE-2026-88772 exploitation beginning by early September across North American and European government, financial, technology, education, legal, and professional-services organizations. The published web-shell artifacts, headers, URI paths, IP addresses, and process behaviors are confirmed observations; GTIG states it does not possess exploit code and describes the DTLS packet mechanics as an assessment based on frontline telemetry.

What this hunt looks for

DTLS handshake failures correlated with NSPPE crashes, pitboss restart failures, malicious Apache handler or alias changes, disguised .deb and .sig web shells, WHIPSHOT and SLAPSHOT artifacts, deceptive 404 responses, unexpected appliance egress, internal fan-out, and published staging IPs.

Required logs

NetScaler ns.log and FreeBSD /var/log/messages through Syslog; NetScaler web access and error logs, AppFlow, or CommonSecurityLog; firewall or flow data for appliance ingress and egress; and endpoint network telemetry for downstream IOC correlation. Standard ns.log forwarding alone is insufficient for several confirmed artifacts.

Hunt 1 — DTLS internal-error handshake followed by NSPPE termination

let Handshakes=Syslog
| where TimeGenerated > ago(30d)
| where SyslogMessage has_all ("SSL_HANDSHAKE_FAILURE","DTLSv1.0") and SyslogMessage has "Handshake failure-Internal Error"
| project Computer,HandshakeTime=TimeGenerated,HandshakeMessage=SyslogMessage;
let Crashes=Syslog
| where TimeGenerated > ago(30d)
| where SyslogMessage has_any ("NSPPE","pitboss") and SyslogMessage has_any ("exit with orphan rings","NOT restarting","terminated","core")
| project Computer,CrashTime=TimeGenerated,CrashMessage=SyslogMessage;
Handshakes
| join kind=inner Crashes on Computer
| where CrashTime between (HandshakeTime..HandshakeTime+5m)
| project Computer,HandshakeTime,CrashTime,HandshakeMessage,CrashMessage
| order by HandshakeTime desc

Hunt 2 — CVE-2026-88772 DTLS handshake-failure clusters

Syslog
| where TimeGenerated > ago(30d)
| where SyslogMessage has_all ("SSL_HANDSHAKE_FAILURE","DTLSv1.0") and SyslogMessage has "Handshake failure-Internal Error"
| summarize Events=count(),FirstSeen=min(TimeGenerated),LastSeen=max(TimeGenerated),Samples=make_set(SyslogMessage,10) by Computer,bin(TimeGenerated,10m)
| order by Events desc

Hunt 3 — NSPPE crash, pitboss failure, or appliance restart evidence

Syslog
| where TimeGenerated > ago(30d)
| where SyslogMessage has_any ("NSPPE","pitboss","nsshutdown")
| where SyslogMessage has_any ("exit with orphan rings","NOT restarting","segfault","terminated","core","-R","restart")
| project TimeGenerated,Computer,Facility,SeverityLevel,ProcessName,SyslogMessage
| order by TimeGenerated desc

Hunt 4 — Unauthorized PHP handlers, aliasing, or SUID shell changes

Syslog
| where TimeGenerated > ago(30d)
| where SyslogMessage has_any ("/etc/httpd.conf","/nsconfig/httpd.conf","/flash/nsconfig/httpd.conf","chmod u+s /bin/sh","AddHandler application/x-httpd-php","AliasMatch","php_flag engine on")
| project TimeGenerated,Computer,ProcessName,SeverityLevel,SyslogMessage
| order by TimeGenerated desc

Hunt 5 — Disguised web-shell and SLAPSHOT artifacts in appliance logs

Syslog
| where TimeGenerated > ago(30d)
| where SyslogMessage has_any ("/vpn/scripts/linux/","/vpn/media/","nsginstaller","nsgclient",".uxdport",".uxdlock","HTTP_X_UX","HTTP_NSC_LDAP","HTTP_NSC_CLIENTTYPE")
| where SyslogMessage has_any (".deb",".sig",".php",".ico",".uxdport",".uxdlock","HTTP_")
| project TimeGenerated,Computer,ProcessName,SeverityLevel,SyslogMessage
| order by TimeGenerated desc

Hunt 6 — Malicious command headers or masquerading URI paths in normalized security logs

union isfuzzy=true
(CommonSecurityLog | where TimeGenerated > ago(30d) | extend RawEvent=strcat(RequestURL," ",AdditionalExtensions," ",Message) | project TimeGenerated,DeviceName,SourceIP,DestinationIP,RawEvent),
(Syslog | where TimeGenerated > ago(30d) | extend RawEvent=SyslogMessage | project TimeGenerated,DeviceName=Computer,SourceIP="",DestinationIP="",RawEvent)
| where RawEvent has_any ("HTTP_NSC_LDAP","HTTP_NSC_CLIENTTYPE","HTTP_X_UX","/vpn/media/nsgclient.ico","/vpn/scripts/linux/nsginstaller","/vpn/scripts/linux/nsgclient")
| order by TimeGenerated desc

Hunt 7 — NetScaler web requests returning deceptive 404 responses with large payloads

CommonSecurityLog
| where TimeGenerated > ago(30d)
| extend Url=tostring(RequestURL),ResponseCode=tostring(DeviceResponseClassID),Bytes=tolong(column_ifexists("ReceivedBytes",0))
| where Url has_any ("/vpn/media/","/vpn/scripts/","/vpn/theme/")
| where Url matches regex @"(?i)\.(ico|sig|deb|php|rpm|tgz|dat|html)(\?|$)"
| where ResponseCode == "404" or DeviceAction has "404"
| where Bytes > 5000 or isnull(Bytes)
| project TimeGenerated,DeviceName,SourceIP,DestinationIP,RequestMethod,Url,ResponseCode,Bytes,DeviceAction,AdditionalExtensions
| order by TimeGenerated desc

Hunt 8 — Rare outbound destinations and internal fan-out from NetScaler appliances

let Baseline=CommonSecurityLog
| where TimeGenerated between (ago(30d)..ago(1d))
| where DeviceVendor has_any ("Citrix","NetScaler") or DeviceProduct has "NetScaler"
| summarize by SourceIP,DestinationIP,DestinationPort;
CommonSecurityLog
| where TimeGenerated > ago(1d)
| where DeviceVendor has_any ("Citrix","NetScaler") or DeviceProduct has "NetScaler"
| join kind=leftanti Baseline on SourceIP,DestinationIP,DestinationPort
| summarize FirstSeen=min(TimeGenerated),LastSeen=max(TimeGenerated),Connections=count(),Ports=make_set(DestinationPort,30) by SourceIP,DestinationIP
| order by Connections desc

Hunt 9 — Published exploitation and staging IP addresses

let IOCs=dynamic(["143.198.7.94","157.254.167.12"]);
union isfuzzy=true
(CommonSecurityLog | where TimeGenerated > ago(90d) and (SourceIP in (IOCs) or DestinationIP in (IOCs)) | project TimeGenerated,DeviceName,Evidence="Firewall",SourceIP,DestinationIP,DestinationPort,Detail=Message),
(DeviceNetworkEvents | where TimeGenerated > ago(90d) and (RemoteIP in (IOCs) or LocalIP in (IOCs)) | project TimeGenerated,DeviceName,Evidence="EndpointNetwork",SourceIP=LocalIP,DestinationIP=RemoteIP,DestinationPort=RemotePort,Detail=InitiatingProcessCommandLine)
| order by TimeGenerated desc

Detection Notes

  • Hunt 1 is the highest-signal exploitation sequence because GTIG observed the DTLS error followed by NSPPE termination. Either event should still be reviewed independently because collection gaps can break the join.
  • Standard NetScaler Syslog forwarding may omit /var/log/messages, web logs, and file-integrity events. Missing those sources prevents detection of several confirmed behaviors.
  • Upstream firewalls generally cannot inspect malicious HTTP headers or decrypted URI paths because TLS terminates on the appliance.
  • A 404 response is not inherently malicious. Prioritize .ico, .sig, or .deb requests with large responses, command headers, configuration changes, or nearby appliance crashes.
  • Endpoint Device* coverage is usually absent on NetScaler appliances. Network and Syslog telemetry are therefore primary.
  • The two IP indicators are not exhaustive and may later be reused or retired. Behavioral persistence and crash correlation carry more durable value.