CVE-2026-88771 (CVSS score: 9.5) is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands on Citrix NetScaler ADC and NetScaler Gateway appliances.
How the flaw surfaced and the urgency from NCSC-NL
The vulnerability and a related bug, CVE-2026-88772, were disclosed last week after reports that the Dutch National Cyber Security Centre (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands urging them to shut their appliances down, citing active exploitation. As of the reporting, there are no public details about who is behind the exploitation activity.
What LevelBlue's THOR team observed in attack telemetry
LevelBlue's Threat Hunt Operations & Research (THOR) team analyzed exploitation activity across multiple customer environments and identified malicious NetScaler authentication events containing attacker-controlled usernames designed to weaponize CVE-2026-88771. "One of the most consistent characteristics across the identified events was attacker-controlled authentication data containing variations of the pitboss and NSPPE strings associated with exploitation of CVE-2026-88771," LevelBlue said.
Observed techniques included simple command tests such as whoami as well as attempts to fetch further payloads and configuration data with curl or wget. LevelBlue listed several external retrieval endpoints used in observed attempts:
- 64.94.85[.]67:443/update_c08937.pl
- 31.56.197[.]72:9090/lula
- 23.27.143[.]20:9000/main.py
"Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation," LevelBlue said. The activity included payload retrieval and execution as well as collection and staging of NetScaler configuration data.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleSecond-stage payloads: what the scripts do on compromised appliances
LevelBlue documented at least two notable second-stage payloads that show post-exploitation capabilities beyond simple remote code execution.
- Main Python payload ("main.py"): designed to establish a reverse shell to 45.141.21[.]130 over TCP port 443 and to search for running processes associated with /var/python/bin/customsnmpd, forcefully terminating them with kill -9.
- Perl updater ("update_c08937.pl"): implements multiple persistence and data-exfiltration steps:
- Modify /flash/nsconfig/ns.conf to create a local account named sec_monitor and assign it the superuser role.
- Archive the /flash/nsconfig directory to /tmp/update_result_3567cs.tgz, upload that archive containing NetScaler configuration data to 64.94.85[.]67:443, then delete the archive and erase itself.
- Change permissions of /bin/sh to 6555 and deploy a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal for remote command execution and file upload/download.
- Modify /etc/httpd.conf to enable PHP execution and map the web shell to URLs resembling legitimate NetScaler CSS resources — an activity GreyNoise corroborated.
Mandiant, Google Threat Intelligence Group, and related web-shell tooling
The disclosure from LevelBlue followed a separate notice from Mandiant Consulting and the Google Threat Intelligence Group (GTIG). Those groups said dozens of organizations have been impacted by attacks exploiting CVE-2026-88772 to deliver PHP web shells such as WHIPSHOT and a Python tunneler dubbed SLAPSHOT. LevelBlue's findings show parallel activity with payload retrieval, reverse shells, privileged account creation, configuration archiving, and web-shell deployment.
What this means for technologists, affected enterprises, and regulators
- Technologists and security teams: look for anomalous authentication strings (variations of pitboss and NSPPE), evidence of retrieved payloads from the listed IPs, the presence of a sec_monitor superuser in /flash/nsconfig/ns.conf, unexpected /tmp/update_result_*.tgz archives or uploads to 64.94.85[.]67, modifications to /etc/httpd.conf, or a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal. Corroborating indicators include reverse-connection attempts to 45.141.21[.]130:443 and execution traces of commands such as kill -9 against /var/python/bin/customsnmpd.
- Affected enterprises and procurement leaders: the NCSC-NL pre-notification recommending appliance shutdown underscores the operational trade-offs organizations face when critical, pre-auth command-injection vulnerabilities are actively exploited. Presence of configuration exfiltration and account creation increases the urgency of containment and forensic review.
- Policymakers and regulators: multiple public advisories and cross-organizational reporting — including NCSC-NL, LevelBlue, Mandiant, and GTIG — indicate active exploitation and the potential for broad operational impact on organizations using the affected Citrix NetScaler appliances.
The observed activity shifts the incident from a straightforward pre-auth exploit to a multi-stage campaign that attempts persistent access and configuration theft. LevelBlue's telemetry ties specific payloads and network endpoints to the post-exploitation behavior; the question left on the table is whether detection and rapid containment will outpace attackers who now employ superuser creation and web-shell mapping to blend malicious functionality into legitimate-looking resource URLs.
https://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html




