THREAT actors have exploited a critical pre-authentication command injection flaw in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and harvest configuration data. LevelBlue’s THOR team found malicious authentication events that used attacker-controlled usernames linked to CVE-2026-88771, an unvalidated input condition rated critical (CVSS 9.5).
The two CVEs were disclosed after advisories from the Dutch National Cyber Security Centre urging organisations to take NetScaler appliances offline due to active exploitation. The activity appears more extensive than simple verification, with attackers fetching additional payloads and attempting to exfiltrate configuration data.
In the observed post-exploitation activity, multiple second-stage payloads were used. A Python script named main[.]py opened a reverse shell to 45.141.21[.]130 over TCP 443 and terminated processes tied to /var/python/bin/customsnmpd. A Perl script, update_c08937.pl, created a local superuser account sec_monitor by modifying /flash/nsconfig/ns[.]conf, archived /flash/nsconfig to /tmp/update_result_3567cs.tgz and uploaded it to 64.94.85[.]67:443, then deleted the archive and itself.
It also set /bin/sh permissions to 6555 and deployed a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal, while updating /etc/httpd[.]conf to enable PHP execution and map the shell to URLs resembling legitimate NetScaler CSS resources.
LevelBlue noted these 2nd-stage actions—including shell deployment, privileged account creation, data collection, and remote command execution—align with a broader exploitation pattern. corroborating indicators of compromise include attacker-controlled usernames and CSS-like URL mappings; GreyNoise reported related exploitation activity.