Security1 publisher2 min readPublished
Pre-auth NetScaler exploit plants a superuser account and hidden web shells
LevelBlue says attackers are exploiting NetScaler flaw CVE-2026-88771, rated 9.5, to create a hidden superuser account and plant web shells. The patch closes the injection but removes neither, so already-exposed appliances need a compromise check.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- An edit to httpd.conf maps the PHP web shell to URLs that resemble legitimate NetScaler CSS files, matching activity GreyNoise observed.
- The Dutch NCSC reportedly told organizations in the Netherlands to shut their NetScaler appliances down, citing active exploitation.
- Mandiant and Google's Threat Intelligence Group reported dozens of organizations hit through companion flaw CVE-2026-88772, which planted web shells like WHIPSHOT and a tunneler called SLAPSHOT.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Any appliance exposed before the update has to be treated as compromised and hunted for the sec_monitor account and the .local_journal shell, not just patched.
- exposure The NetScaler configuration was archived and shipped to an external host, so whatever it held is in attacker hands even after the box is patched.
- constraint The Perl script wipes itself and its archive, leaving a thin on-disk trail; detection leans on the pitboss and NSPPE strings in auth logs and the planted artifacts.
- precedent Two CVEs were disclosed together and the companion bug already drove dozens of confirmed intrusions, so NetScaler owners face a campaign across both flaws, not a single bug.
The flaw is improper input validation, scored 9.5, and it lets an unauthenticated attacker run commands on NetScaler ADC and NetScaler Gateway [2]. LevelBlue's Threat Hunt Operations & Research team pulled the activity from multiple customer environments and found attacker-controlled usernames inside NetScaler authentication events, crafted to trigger the bug [3].
The clearest signal is in the authentication data. "One of the most consistent characteristics across the identified events was attacker-controlled authentication data containing variations of the pitboss and NSPPE strings associated with exploitation of CVE-2026-88771," LevelBlue said [4]. Some attempts used curl or wget to pull second-stage payloads from external hosts or to extract configuration data [5].
The persistence sits in a Perl script, update_c08937.pl. It edits ns.conf to add a local account called sec_monitor and gives it the superuser role [6]. It then changes the permissions on /bin/sh to 6555, drops a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal, and edits httpd.conf so the shell answers on URLs that look like ordinary NetScaler CSS files, matching what GreyNoise saw [8][9]. Before it finishes, it archives /flash/nsconfig, ships the archive to 64.94.85.67 over port 443, then deletes the archive and erases itself [7].
A second payload, the Python main.py, opens a reverse shell to 45.141.21.130 on TCP 443 and kills any customsnmpd process with kill -9 [10].
The patch fixes the input validation. It does not delete the sec_monitor account or the web shell, and the configuration archive is already offsite [2][6][7]. "While some attempts used commands such as whoami to test command execution, others attempted to retrieve additional payloads, collect NetScaler configuration data, establish reverse shells, create privileged accounts, and deploy web shells," LevelBlue said [11].
LevelBlue says there are no details yet on who is behind the campaign [12]. CVE-2026-88771 was disclosed last week alongside CVE-2026-88772 [13], after the Dutch NCSC reportedly told organizations in the Netherlands to shut their appliances down over active exploitation [14]. A day before LevelBlue published, Mandiant Consulting and Google's Threat Intelligence Group said dozens of organizations had been hit through the companion flaw CVE-2026-88772, used to plant PHP web shells including WHIPSHOT and a Python tunneler called SLAPSHOT [15].
What to watch
- Whether any researcher or agency names the actor behind the CVE-2026-88771 payloads, which the current reporting does not.
- Whether CISA or Citrix expand the indicator set and add both NetScaler CVEs to a known-exploited catalog.
- How the confirmed count of sec_monitor accounts and .local_journal shells grows as more environments are hunted.