Overview / Introduction
On September 29, 2026, Citrix disclosed two unpatched vulnerabilities-CVE-2026-88771 and CVE-2026-88772-affecting all NetScaler ADC and Gateway deployments. While the former is an unauthenticated remote code execution flaw, the latter is a memory-overflow bug that, when exploited, can lead to remote code execution or a denial-of-service (DoS) when DTLS is enabled. In the wild, attackers have leveraged CVE-2026-88772 to deploy custom PHP web shells, gain root-level access, steal credentials, and move laterally inside victim networks. The campaign has already impacted government, financial services, education, legal, and professional services organizations across North America and Europe.
Technical Details
The exploitation chain begins with an authentication bypass that crashes the NetScaler Packet Processing Engine (PPE). Attackers then inject code that modifies /bin/sh permissions, installs a PHP web shell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver, and rewrites /etc/httpd.conf so that requests for CSS files (e.g., receiver.min.css) are redirected to the hidden shell. The shell is password-protected, allowing attackers to execute arbitrary commands as the root user.
# Example payload used by GreyNoise
PUT /cgi-bin/receiver.min.css HTTP/1.1
Host: victim.net
Content-Type: application/x-www-form-urlencoded
cmd=sed+in+file+%2Fetc%2Fhttpd.conf+%2Fetc%2Fhttpd.conf+%2Fetc%2Fhttpd.conf
Because the exploit bypasses authentication, it can be executed from any network location with basic HTTP access to the appliance. The memory-overflow triggers a crash in the PPE, which the attacker then uses to execute the shell code. The root access gained allows the attacker to read, modify, or delete configuration files, extract credentials, and pivot to backend systems.
Impact Analysis
All NetScaler ADC and Gateway appliances that have not applied the 29-Sept patches are vulnerable. The impact is especially severe for deployments using SAML authentication, as attackers can compromise the SAML identity provider and then use the web shell to spread credentials to internal services. Organizations that rely on NetScaler for load balancing, SSL off-loading, or gateway functions are at risk of full system compromise, data exfiltration, and extensive lateral movement.
Timeline of Events
- Early September 2026 - Initial exploitation observed by security teams; attackers modify /bin/sh and install web shell.
- September 24, 2026 - GreyNoise records an attempt to exploit a NetScaler Gateway from 149.104.78.141, before public CVE disclosure.
- September 29, 2026 - Citrix publicly discloses CVE-2026-88771 and CVE-2026-88772, labels them “PitScaler,” and releases patches.
- September 30-October 5, 2026 - Active exploitation continues; multiple organizations report root-level compromises and credential theft.
Mitigation / Recommendations
- Apply the official Citrix patches for CVE-2026-88771 and CVE-2026-88772 immediately.
- Disable DTLS on NetScaler appliances if it is not required for your environment.
- Audit file permissions on
/bin/shand/etc/httpd.conf; ensure they have not been altered. - Search for the file
.ctxs.receiveror any suspicious PHP files under/var/netscaler/logon/LogonPoint/custom/. - Review and harden SAML configurations; enforce strict signing and certificate validation.
- Implement network segmentation and micro-segmentation to limit lateral movement from the appliance to critical assets.
- Enable logging and real-time alerts for unexpected configuration changes and root-level command execution.
Real-World Impact
Organizations that rely on NetScaler for secure web access or application delivery now face the reality of root-level compromise. Once inside, attackers can exfiltrate sensitive data, steal user credentials, and pivot to databases, file servers, or cloud workloads. The presence of web shells also provides a persistent foothold that can be leveraged for long-term espionage or ransomware deployment. Early reports indicate that at least 15 large enterprises and 3 government agencies have confirmed root compromise and credential theft.
Expert Opinion
From a cybersecurity standpoint, CVE-2026-88772 is a stark reminder of the fragility of legacy appliance ecosystems. The fact that attackers can bypass authentication entirely and crash the PPE demonstrates a gap in Citrix’s design that should have been mitigated with proper input validation and sandboxing. The rapid spread of the exploit underscores the importance of timely patch management and the need for continuous monitoring for anomalous configuration changes. For the industry, this incident signals a shift toward more aggressive exploitation of zero-day vulnerabilities in edge devices, pushing vendors to adopt zero-trust architectures and to treat all appliances as potential pivot points rather than isolated components.