Skip to content

Security1 publisher2 min readPublished

Public exploit for CVE-2026-88771 turns a quiet NetScaler zero-day into internet-wide attacks

A public proof-of-concept for CVE-2026-88771 pushed a stealthy NetScaler zero-day into mass exploitation, with fewer than 10% of exposed hosts patched. Citrix admits its detection script may miss intrusions, so exposed appliances should be treated as breached.

The Watch · Security desk

Illustration accompanying Public exploit for CVE-2026-88771 turns a quiet NetScaler zero-day into internet-wide attacks

What happened

  • Citrix confirmed the attacks by shipping patches for eight critical and high-risk flaws, and said two of them, CVE-2026-88771 and CVE-2026-88772, were already being exploited as zero-days.
  • Within minutes of watchTowr Labs releasing a proof-of-concept, the deception firm Lupovis was logging live, opportunistic scans of the whole internet for exposed, unpatched appliances.
  • No public proof-of-concept has surfaced yet for CVE-2026-88772, the other vulnerability the initial attackers exploited before disclosure.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure With a working PoC circulating and default configurations exploitable before authentication, an unpatched appliance is a target simply for being reachable from the internet.
  • decision Patching closes the hole but does not show whether an intruder already got in; an appliance that was exposed now warrants a breach assumption and forensic review, not just an update.
  • constraint An external scan cannot separate a breached NetScaler from a clean one, so verification has to run on the appliance itself.
  • precedent For the next NetScaler-class flaw, assume the gap between a public PoC and internet-wide exploitation is minutes, not the days defenders once had.

Attackers poison the appliance logs [11]. Bellekens said Lupovis captured POST requests to /nf/auth/doAuthentication.do carrying the string 'pitboss PPE unexpectedly died NSPPE' in the body, and that outbound DNS lookups ending in instances.httpworkbench.com mean a host in the estate has already been hit [12]. Harvested data goes to a Hetzner server at 138.199.200.90 [11]. CERT-EU published its own technical detail and hunting advice after opening an investigation [13].

GreyNoise recorded a zero-day attempt against a NetScaler Gateway on September 24, more than three days before Citrix disclosed [5]. The attacker failed against a GreyNoise sensor; it tried to gain admin access, hide a webshell behind a fake stylesheet address, clear the logs, and restart the server [7]. 'Though the adversary was unsuccessful in gaining a foothold on the targeted Swarm sensor, their post-exploitation playbook was revealed,' the firm said [6]. Rumors of exploitation had circulated since late last week [21]. 'If you run NetScaler and you haven't patched, assume you are already being probed,' Bellekens said [10].

Censys counts about 42,000 internet-facing NetScaler ADC and Gateway hosts and says it cannot tell which are vulnerable or breached [14]. Beaumont's firmware-version scanning implies more than 37,800 of them are unpatched [17][1]. More than three quarters of the hosts sit outside the ten largest networks, with Microsoft carrying 4,254 (10%) and Amazon 3,013 (7%), consistent with VPX virtual appliances in public cloud [16].

Citrix says its detection script 'might fail to identify actual compromises' because attackers change their tools and infrastructure [4]. Beaumont is tracking more than 100 victim organizations, and said 'each one has a unique webshell which can't be scanned for remotely unless you're the attacker' [18]. He believes the first wave was after espionage [19].

What to watch

  • A public PoC for CVE-2026-88772 would open the second zero-day to the same opportunistic exploitation now hitting CVE-2026-88771.
  • Whether Citrix or CERT-EU issues detection that catches the unique per-victim webshells current scans cannot see.
  • Attribution of the initial espionage-focused operator, and whether it overlaps with the opportunistic wave now scanning.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories