Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data.
LevelBlue’s Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler authentication events containing attacker-controlled usernames designed to weaponize CVE-2026-88771.
CVE-2026-88771 (CVSS score: 9.5) is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
The security flaw, along with CVE-2026-88772, was disclosed last week after reports that the Dutch National Cyber Security Centre (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands that urged organizations to shut their appliances down, citing active exploitation. As of writing, there are currently no details about who is behind these efforts.
“One of the most consistent characteristics across the identified events was attacker-controlled authentication data containing variations of the pitboss and NSPPE strings associated with exploitation of CVE-2026-88771,” LevelBlue said.
Other attempts have been observed using curl or wget to fetch additional payloads from external servers, or extract NetScaler configuration data –
“Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation,” LevelBlue said. “The attempts included payload retrieval and execution as well as collection and staging of NetScaler configuration data.”
Notable among the second-stage payloads is a Python script (“main.py”) that’s designed to establish a reverse shell to “45.141.21[.]130” over TCP port 443. It also searches for running processes associated with “/var/python/bin/customsnmpd” and forcefully terminates them by issuing a “kill -9” command.
Another second-stage payload, “update_c08937.pl,” is a Perl script with several post-exploitation capabilities –
Leave a Reply