NetScaler Attack Payloads Aim for Superuser Persistence and CSS-Masked Web Shells
Attackers exploit CVE-2026-88771 on NetScaler to deploy reverse shells, create sec_monitor superuser, steal configs and hide PHP web shells as CSS.
Illustrative image generated with AI
Attackers exploiting Citrix NetScaler appliances have moved beyond simple command-execution tests, using second-stage payloads designed to establish reverse shells, create privileged accounts, stage configuration data and deploy web shells.
LevelBlue’s Threat Hunt Operations & Research team observed the activity across multiple customer environments. The malicious authentication events targeted CVE-2026-88771, a pre-authentication command-injection vulnerability affecting NetScaler ADC and NetScaler Gateway.
The researchers documented attempts to collect and stage appliance configurations, but the reporting does not confirm that every payload action succeeded. One analyzed Perl script is capable of creating a sec_monitor superuser, preparing configuration files for exfiltration and exposing a PHP shell through URLs resembling legitimate CSS resources.
A separate NetScaler flaw, CVE-2026-88772, is also being exploited. Both vulnerabilities entered the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog on September 27, 2026. The remediation deadline for federal agencies was September 30, 2026.
Malicious authentication data triggers command execution
LevelBlue identified malicious NetScaler authentication events containing attacker-controlled usernames crafted to exploit CVE-2026-88771. Variations of the strings pitboss and NSPPE appeared repeatedly in the observed authentication data.
Some attempts issued basic commands such as whoami, apparently to determine whether command execution was working. Other events used curl or wget to retrieve additional payloads from external infrastructure or attempted to collect NetScaler configuration data.
Taken together, the activity extended beyond vulnerability validation. LevelBlue observed attempts involving payload retrieval and execution, reverse-shell establishment, configuration collection and staging, privileged-account creation, and web-shell deployment.
The reporting does not attribute the activity to a specific threat actor.
Python payload targets a process and opens a reverse shell
One second-stage payload was a Python script named main.py, retrieved from:
23.27.143[.]20:9000/main.py
The script is designed to establish a reverse shell to 45.141.21[.]130 over TCP port 443. Although that port is commonly associated with HTTPS, the available analysis does not identify the shell traffic itself as HTTPS.
The payload also searches for processes associated with:
/var/python/bin/customsnmpd
It then attempts to terminate matching processes with kill -9. The analysis documents this behavior without establishing why the process was selected.
For defenders, relevant traces include outbound connections to the reported destination, retrieval of main.py, and unexpected termination of the customsnmpd-related process. These artifacts should be considered alongside authentication and command-execution records rather than treated as standalone proof of compromise.
Perl script can create sec_monitor and stage configurations
The more extensive payload, update_c08937.pl, was retrieved from:
64.94.85[.]67:443/update_c08937.pl
According to LevelBlue’s analysis, the Perl script is capable of modifying /flash/nsconfig/ns.conf to add a local account named sec_monitor and assign it the superuser role. Finding that account or the corresponding configuration changes would indicate that this stage may have executed successfully.
The script is also written to archive /flash/nsconfig into:
/tmp/update_result_3567cs.tgz
It then attempts to upload the archive, which would contain NetScaler configuration data, to 64.94.85[.]67 over port 443. Its programmed cleanup sequence deletes the archive and removes the Perl script itself, reducing the file-based evidence available to investigators if those steps complete.
Additional capabilities include changing /bin/sh permissions to 6555 and placing a PHP web shell at:
/var/netscaler/logon/LogonPoint/.local_journal
The shell supports remote command execution and file transfers. The payload can also alter /etc/httpd.conf to enable PHP execution and map the shell to URLs that resemble legitimate NetScaler CSS resources. LevelBlue said this mapping behavior corroborated activity observed by GreyNoise.
That technique goes beyond choosing an inconspicuous filename. By changing the web-server configuration, the payload can make requests to the shell look like requests for static style-sheet content in URL records.
Another resource location associated with the observed activity was:
31.56.197[.]72:9090/lula
Both flaws affect multiple NetScaler branches
CVE-2026-88771 is classified as CWE-20, Improper Input Validation. It can allow an unauthenticated attacker to execute arbitrary commands on a vulnerable appliance.
The primary article assigns the flaw a CVSS score of 9.5. The NVD record instead lists CVSS v3.1 9.8 with the following vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The affected versions identified in the NVD description are:
- NetScaler ADC before
14.1-73.37 - NetScaler ADC before
13.1-64.23 - NetScaler ADC FIPS before
14.1-73.37 - NetScaler ADC FIPS and NDcPP before
13.1.37.279 - NetScaler Gateway before
14.1-73.37 - NetScaler Gateway before
13.1-64.23
CVE-2026-88772 is a separate vulnerability classified as CWE-119, Improper Restriction of Operations within the Bounds of a Memory Buffer. It can lead to remote code execution or denial of service.
Its NVD CVSS v3.1 score is 8.1:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The same NetScaler product branches and version thresholds are listed for CVE-2026-88772.
Mandiant Consulting and Google Threat Intelligence Group separately reported that dozens of organizations had been affected by attacks exploiting CVE-2026-88772. Those operations delivered PHP web shells including WHIPSHOT and a Python tunneler called SLAPSHOT.
Available reporting does not establish that those incidents and the CVE-2026-88771 activity investigated by LevelBlue involved the same operator.
CISA’s federal remediation deadline has expired
CISA added both vulnerabilities to the KEV catalog on September 27, 2026, confirming that they are exploited vulnerabilities rather than merely theoretical risks. The federal remediation deadline was September 30, 2026.
For both entries, CISA directs stakeholders to apply vendor mitigations and comply with BOD 26-04, “Prioritizing Security Updates Based on Risk,” and its “Forensics Triage Requirements.” Organizations must evaluate each asset’s internet exposure and follow the applicable BOD 26-04 patching guidance.
For cloud services, CISA directs stakeholders to follow the relevant BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. The supplied information does not provide a product-specific installation procedure, so operators should follow Citrix’s instructions for their exact branch and deployment type.
These are not Citrix’s only recent KEV entries. CVE-2026-19490 was added on September 9, 2026, and CVE-2026-8452 entered the catalog on August 26, 2026.
What NetScaler defenders should investigate
Administrators should identify affected ADC and Gateway systems, including FIPS and NDcPP deployments, and apply the vendor’s prescribed remediation. Because exploitation has already been observed, installing updates or mitigations should be accompanied by a review for earlier compromise.
Relevant evidence includes:
- Authentication records containing unexpected usernames or variants of
pitbossandNSPPE - Abnormal execution of
whoami,curlorwgetthrough authentication events - A local
sec_monitoraccount assigned thesuperuserrole - Unauthorized changes to
/flash/nsconfig/ns.conf - The file
/var/netscaler/logon/LogonPoint/.local_journal - Changes to
/etc/httpd.conf, particularly mappings that make PHP content resemble CSS resources /bin/shpermissions set to6555- Evidence that
/tmp/update_result_3567cs.tgzwas created or handled - Retrieval of
main.py,update_c08937.plor the resource namedlula - Connections involving
64.94.85[.]67,31.56.197[.]72,23.27.143[.]20or45.141.21[.]130 - Unexpected termination of processes associated with
/var/python/bin/customsnmpd
The Perl payload’s cleanup capabilities mean missing files alone cannot exclude execution. Account records, configuration changes, web-server mappings, process telemetry and network logs may retain evidence after the staged archive or script has been removed.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2026-88771Critical9.8Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated a
- CVE-2026-88772High8.1Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service




