CITRIX NetScaler ADC and NetScaler Gateway were publicly disclosed as affected by CVE-2026-88771 on 27 September 2026, described as a log-injection based, unauthenticated remote code execution flaw. SOCRadar’s researchers uncovered an autonomous operation, branded NetScaler C2, which mass-scans internet-exposed NetScaler instances, fingerprints their versions, and exploits CVE-2026-88771 to deploy a lightweight polling agent that communicates with a command-and-control (C2) server.
The exploit chain begins with an injection into attacker-controlled text logged by unauthenticated HTTP endpoints, processed by the admautoregd daemon, and culminates in root-level command execution. The framework appears to be Chinese-speaking in origin, with references in code comments and UI strings, and evidence suggests AI-assisted development.
The NetScaler C2 toolkit operates as a four-component, modular pipeline: FOFA-based discovery of up to around 120,000 candidate hosts, version fingerprinting to confirm vulnerability, exploitation with multiple HTTP endpoints (including JSON and form submissions) and a DNS out-of-band beacon as a fallback, and a C2 bot that registers, polls every ~20–30 seconds, and returns hex-encoded results.
Concrete indicators include trigger strings such as pitboss NSPPE-00; and logs showing /s/<bid>|sh and ;# unexpectedly died, along with a dropped agent at /tmp/.nsagent. Affected versions align with Citrix advisories: 14.1 before 14.1-73.37, 13.1 before 13.1-64.23, 14.1-FIPS before 14.1-73.37 FIPS, and 13.1-FIPS/NDcPP before 13.1-37.279. UK organisations should isolate vulnerable systems, upgrade to fixed builds, and monitor for the identified IOCs and C2 beaconing patterns.