Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)
AI Summary
Unit 42 has identified active exploitation of two zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in Citrix NetScaler ADC and Gateway devices. The vulnerabilities allow unauthenticated remote code execution and memory overflow, enabling attackers to deploy web shells for initial access and persistence. Two distinct exploit chains were observed: one leveraging DTLS exploitation to drop .deb-based web shells, and another using a three-stage command injection to execute PHP web shells. Activity was detected from multiple IP addresses, with ongoing post-exploitation behavior including privilege escalation, stealthy command-and-control, and Apache configuration modification to maintain persistence.
AI-extracted · verify before operational use
Indicators of Compromise 22 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 104[.]248[.]244[.]66 | Details → |
| IP | 77[.]83[.]199[.]39 | Details → |
| IP | 78[.]47[.]24[.]217 | Details → |
| IP | 66[.]135[.]19[.]18 | Details → |
| IP | 167[.]99[.]111[.]203 | Details → |
| IP | 142[.]93[.]85[.]227 | Details → |
| IP | 104[.]248[.]74[.]206 | Details → |
| IP | 137[.]184[.]91[.]207 | Details → |
| IP | 104[.]28[.]247[.]136 | Details → |
| IP | 104[.]28[.]215[.]136 | Details → |
| IP | 104[.]28[.]215[.]137 | Details → |
| IP | 162[.]33[.]178[.]9 | Details → |
| IP | 193[.]149[.]176[.]207 | Details → |
| IP | 45[.]61[.]136[.]143 | Details → |
| IP | 66[.]227[.]183[.]84 | Details → |
| IP | 216[.]245[.]184[.]164 | Details → |
| Filename | /vpn/scripts/linux/nsgclient18.deb | Details → |
| Filename | /vpn/scripts/linux/nsg64.deb | Details → |
| Filename | /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver | Details → |
| SHA-256 | ae22ef2517b5c0fb47f78745b9cb5260acee0e751b89bcd354640ff8bc8d29ec | Details → |
| SHA-256 | 1bd314b661396c7086f6367fbbb48025e03ca2de69c073d53a8b0a38aa5fbb7d | Details → |
| SHA-256 | 79c65fa04541032e251fa4796b97800374b63c7982593dd1a2e0db605d429186 | Details → |