unit42 · Crawled Oct 2, 2026

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)

22 IoCs
Read original article ↗

AI Summary

Unit 42 has identified active exploitation of two zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in Citrix NetScaler ADC and Gateway devices. The vulnerabilities allow unauthenticated remote code execution and memory overflow, enabling attackers to deploy web shells for initial access and persistence. Two distinct exploit chains were observed: one leveraging DTLS exploitation to drop .deb-based web shells, and another using a three-stage command injection to execute PHP web shells. Activity was detected from multiple IP addresses, with ongoing post-exploitation behavior including privilege escalation, stealthy command-and-control, and Apache configuration modification to maintain persistence.

AI-extracted · verify before operational use

Indicators of Compromise 22 extracted

Type Value Detail
IP 104[.]248[.]244[.]66 Details →
IP 77[.]83[.]199[.]39 Details →
IP 78[.]47[.]24[.]217 Details →
IP 66[.]135[.]19[.]18 Details →
IP 167[.]99[.]111[.]203 Details →
IP 142[.]93[.]85[.]227 Details →
IP 104[.]248[.]74[.]206 Details →
IP 137[.]184[.]91[.]207 Details →
IP 104[.]28[.]247[.]136 Details →
IP 104[.]28[.]215[.]136 Details →
IP 104[.]28[.]215[.]137 Details →
IP 162[.]33[.]178[.]9 Details →
IP 193[.]149[.]176[.]207 Details →
IP 45[.]61[.]136[.]143 Details →
IP 66[.]227[.]183[.]84 Details →
IP 216[.]245[.]184[.]164 Details →
Filename /vpn/scripts/linux/nsgclient18.deb Details →
Filename /vpn/scripts/linux/nsg64.deb Details →
Filename /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver Details →
SHA-256 ae22ef2517b5c0fb47f78745b9cb5260acee0e751b89bcd354640ff8bc8d29ec Details →
SHA-256 1bd314b661396c7086f6367fbbb48025e03ca2de69c073d53a8b0a38aa5fbb7d Details →
SHA-256 79c65fa04541032e251fa4796b97800374b63c7982593dd1a2e0db605d429186 Details →