Full Report
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. [...]
Analysis Summary
# Vulnerability: Citrix NetScaler Remote Code Execution (PitScaler)
## CVE Details
- **CVE ID:** CVE-2026-88772 (Primary focus of report) and CVE-2026-88771
- **CVSS Score:** Not explicitly listed in text, but categorized as Critical/Zero-day.
- **CWE:** Memory Overflow / Heap memory boundary corruption (CVE-2026-88772).
## Affected Systems
- **Products:** Citrix NetScaler ADC and Citrix NetScaler Gateway.
- **Versions:** All deployments are considered affected by CVE-2026-88771; versions with DTLS enabled are specifically vulnerable to CVE-2026-88772.
- **Configurations:**
- CVE-2026-88772: Requires **DTLS** (Datagram Transport Layer Security) to be enabled.
- CVE-2026-88771: Affects all standard deployments (unauthenticated RCE).
## Vulnerability Description
CVE-2026-88772 is a memory overflow vulnerability within the NetScaler Packet Processing Engine (NSPPE). Attackers transmit malformed or fragmented record headers that induce heap memory boundary corruption. This diverts the control flow to execute arbitrary shellcode, granting the attacker root-level operating system privileges on the underlying FreeBSD platform.
## Exploitation
- **Status:** Exploited in the wild (Zero-day). Attacks observed since early September 2026.
- **Complexity:** Low (Authentication bypass).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Root access, credential theft, internal network lateral movement).
- **Integrity:** High (Modification of system binaries like `/bin/sh` and configuration files like `httpd.conf`).
- **Availability:** High (Can lead to denial of service via NSPPE crashes).
## Remediation
### Patches
- Citrix has released security updates to address both flaws. Organizations are advised to install the latest versions of NetScaler ADC and Gateway immediately. (Refer to Citrix KB **CTX697096**).
### Workarounds
- **For CVE-2026-88772:** Disable DTLS where operationally feasible or block inbound UDP/443 at the firewall level.
- **Note:** These workarounds **do not** protect against CVE-2026-88771. Patching is the only comprehensive remediation.
## Detection
- **Indicators of Compromise (IoCs):**
- Presence of file: `/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver`
- Presence of files: `/tmp/.uxdport` or `/tmp/.uxdlock` (associated with SLAPSHOT malware).
- Modification of `/bin/sh` permissions (e.g., setuid bit asserted).
- Unauthorized `Alias` or `AliasMatch` entries in `/etc/httpd.conf` pointing to PHP web shells disguised as `.css`, `.deb`, or `.sig` files.
- **Detection Methods:**
- Monitor for unexpected crashes of the NetScaler Packet Processing Engine (NSPPE).
- Inspect for unusual HTTP 404 responses or suspicious Python processes launched with `nohup` containing Base64 payloads.
- Review logs for connections from IP: `149.104.78[.]141`.
## References
- Citrix Advisory: [https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096]
- Mandiant Research: [https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances]
- GreyNoise Analysis: [https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation]