Palo Alto Networks counted 50,277 internet-exposed Citrix NetScaler ADC and Gateway systems as of September 27, 2026. Two zero-days, CVE-2026-88771 and CVE-2026-88772, have been under active exploitation since at least August 21. Patches are available and you should apply them immediately. But there is a problem: Unit42's threat brief, updated September 30, states plainly that "updating and patching will not remove access for attackers that have already established persistence."
That sentence is the most important thing your IR team needs to know about this incident.
What the vulnerabilities do
CVE-2026-88771 (CVSS 9.5) is a remote code execution flaw caused by improper input validation in Citrix NetScaler ADC and Gateway. Exploitation uses a three-stage chain:
- Stage 1: A Base64-encoded dropper is embedded in the User-Agent HTTP header, which is logged to httpaccess-vpn.log.
- Stage 2: A poisoned login failure message containing the second payload is written to ns.log.
- Stage 3: A vulnerable Perl script at /netscaler/ns_monuploadd_err.pl reads from those logs and executes the extracted commands.
CVE-2026-88772 (CVSS 9.5) exploits DTLS traffic to trigger memory corruption, delivering additional payloads after initial access is established via the first flaw.
Together, these vulnerabilities give an unauthenticated remote attacker a path from zero to root on a NetScaler appliance, using only standard HTTP and DTLS traffic that can blend with legitimate activity.
The web shells
Attackers deployed PHP-based web shells with RC4 encryption. The RC4 key is derived from the MD5 hash of the string "Rhfajaf1H992." Capabilities include remote command execution, file exfiltration, and privilege escalation through SUID binary abuse. The shells survive reboots and firmware updates, which is why Unit42's patching warning holds.
Initial reconnaissance traced to IP addresses 104.248.244[.]66, 77.83.199[.]39, and 78.47.24[.]217, with peak exploitation activity between September 4 and September 24. Attackers rotated through Cloudflare WARP addresses to obscure their origin.
What patching does and does not do
Applying the vendor patch closes the vulnerability that allowed initial entry. It does not remove installed web shells, attacker-created accounts or modified credentials, persisted cron jobs or startup scripts, or files already exfiltrated.
Any NetScaler system that was internet-exposed between late August and today should be treated as potentially compromised regardless of its current patch state. Patching is step one. Step two is forensic analysis.
What to check
If you run NetScaler ADC or Gateway, Unit42 recommends reviewing httpaccess-vpn.log and ns.log for anomalous Base64-encoded payloads or unexpected login failure entries. Scan the filesystem for unexpected PHP files, especially in directories not normally containing web-accessible scripts. Check for SUID binaries modified after late August, review user accounts for additions or privilege changes, and verify whether unexpected DTLS traffic appeared in your network logs during the exploitation window.
CISA added both CVEs to the KEV catalog on September 27. The full technical attack chain is documented in Unit42's threat brief, which is required reading before your IR team starts the investigation.
Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if your team is working through a post-exploitation investigation on network appliances.