On April 2026, Unit 42 published a threat brief confirming what many of us in the IR community had already suspected from telemetry spikes: two previously unknown vulnerabilities in NetScaler ADC and NetScaler Gateway — tracked as CVE-2026-88771 and CVE-2026-88772 — are being exploited in the wild against unpatched devices. Citrix has acknowledged the flaws and released mitigation guidance, and Palo Alto Networks' Unit 42 is tracking observed attack activity targeting internet-facing appliances.
If you operate NetScaler ADC or NetScaler Gateway as a remote access gateway, load balancer, or VPN concentrator, treat this as an active incident scenario, not a routine patch cycle. Edge appliances sit at the trust boundary of your network. A compromised NetScaler is not just a vulnerable device — it is a beachhead with visibility into authentication traffic, session tokens, and internal network topology. In every major NetScaler campaign I've responded to over the past several years, the organizations that suffered the deepest impact were the ones that patched but never hunted for pre-patch compromise.
This post breaks down what we know, how to hunt, and how to remediate — in that order of operational priority.
Technical Analysis
What's Confirmed
- CVE-2026-88771 and CVE-2026-88772 — two distinct vulnerabilities affecting NetScaler ADC and NetScaler Gateway appliances.
- Exploitation status: CONFIRMED IN THE WILD. Citrix reports both CVEs have been exploited, and Unit 42 is tracking unpatched vulnerability activity against exposed devices. This is not theoretical, and there is no public grace period here — exploitation preceded broad public disclosure, which is the defining characteristic of zero-day activity.
- Affected platforms: Internet-facing NetScaler ADC and NetScaler Gateway instances. Organizations running these appliances as VPN gateways, AAA/virtual servers, or load balancers for internal applications should assume exposure.
Why NetScaler Zero Days Are Uniquely Dangerous
I've led multiple IR engagements involving compromised edge appliances, and NetScaler incidents follow a consistent pattern that defenders must understand:
- Pre-authentication attack surface. The vulnerable components on these appliances are typically reachable before authentication. An attacker needs nothing more than network reachability to the management or virtual server interface.
- Webshells and memory-resident implants. Post-exploitation on NetScaler almost universally involves dropping webshells into the NetScaler web directory structure (commonly under
/netscaler/portal/,/var/vpn/, or/var/netscaler/gui/) or injecting payloads that persist across reboots via cron jobs or modified rc scripts. - Credential harvesting at scale. Because the appliance terminates authentication sessions, attackers who gain code execution can intercept LDAP/AD bind credentials, session cookies, and MFA tokens — turning a single appliance compromise into a domain-wide identity compromise.
- Patching does not evict the attacker. Firmware updates fix the vulnerability, but they do not remove webshells, rogue cron entries, or attacker-created accounts already staged on the device. This is the single most common failure mode I see in remediation efforts.
Assumed Attack Chain (Defender's Model)
Based on the confirmed exploitation activity and historical NetScaler tradecraft, defenders should hunt for this chain:
- Unauthenticated request to an exposed NetScaler interface triggers the vulnerability (CVE-2026-88771 or CVE-2026-88772).
- The attacker achieves command execution in the context of the NetScaler web services process.
- A webshell or staging script is written to the appliance filesystem — frequently PHP or Perl files under web-accessible paths.
- Persistence is established via crontab modification, rc script tampering, or addition of unauthorized local accounts/SSH keys.
- Outbound C2 or data staging begins from the appliance itself — often over HTTPS to attacker infrastructure, sometimes tunneled through legitimate-looking domains.
Note on scoring: At the time of writing, consult the Citrix security bulletin for the authoritative CVSS scoring and fixed build numbers for each supported release train. Do not wait for a perfect scoring picture to act — confirmed in-the-wild exploitation is the only signal that matters.
Detection & Response
This is a technical threat with confirmed exploitation. The detections below target the post-exploitation behaviors that are consistent across NetScaler compromise campaigns: webshell drops, shell execution from the web service context, persistence tampering, and anomalous egress.
Sigma Rules
---
title: NetScaler Webshell Dropped in Web-Accessible Directory
id: 3f8a2c1d-9b4e-4f7a-bc25-6d1e8a9f0342
status: experimental
description: Detects creation of script files in NetScaler web-accessible directories, a hallmark of post-exploitation webshell staging observed in NetScaler ADC/Gateway compromises including CVE-2026-88771 and CVE-2026-88772 activity.
references:
- https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/
- https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/04/08
tags:
- attack.persistence
- attack.t1505.003
logsource:
category: file_event
product: linux
detection:
selection_paths:
TargetFilename|contains:
- '/netscaler/portal/'
- '/var/vpn/'
- '/var/netscaler/gui/'
- '/netscaler/ns_gui/'
selection_ext:
TargetFilename|endswith:
- '.php'
- '.pl'
- '.cgi'
- '.sh'
condition: selection_paths and selection_ext
falsepositives:
- Legitimate NetScaler customization or theme deployments (rare; validate against change tickets)
level: high
---
title: Shell or Command Execution Spawned by NetScaler Web Service Process
id: 8c1d4e72-3a5b-49f6-ad18-2b7c9e05f613
status: experimental
description: Detects suspicious child processes spawned by NetScaler web service components, consistent with command execution following exploitation of edge appliance vulnerabilities such as CVE-2026-88771 and CVE-2026-88772.
references:
- https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/
- https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/04/08
tags:
- attack.execution
- attack.t1059.004
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|contains:
- 'httpd'
- 'nshttpd'
- 'nginx'
selection_child:
Image|endswith:
- '/sh'
- '/bash'
- '/perl'
- '/python'
- '/curl'
- '/wget'
- '/nc'
- '/base64'
condition: selection_parent and selection_child
falsepositives:
- NetScaler health-check scripts (tune to known script paths in your environment)
level: high
---
title: NetScaler Persistence via Cron or Startup Script Tampering
id: 5e2b7f39-1c84-4d6a-9e03-4a8f1b62c790
status: experimental
description: Detects modification of cron tables or startup scripts on NetScaler appliances, a common persistence mechanism used after edge device exploitation to survive reboots and patching.
references:
- https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/
- https://attack.mitre.org/techniques/T1053/003/
author: Security Arsenal
date: 2026/04/08
tags:
- attack.persistence
- attack.t1053.003
logsource:
category: file_event
product: linux
detection:
selection:
TargetFilename|contains:
- '/etc/crontab'
- '/var/cron/tabs/'
- '/etc/rc.d/'
- '/nsconfig/rc.conf'
- '/flash/nsconfig/'
falsepositives:
- Administrative configuration changes via legitimate NetScaler management sessions (correlate with authenticated admin logins)
level: high
KQL Hunt — Microsoft Sentinel (Syslog/CEF Ingestion from NetScaler)
If you forward NetScaler logs to Sentinel via Syslog or CEF (which you should), hunt for the exploitation and post-exploitation telemetry directly. Also hunt endpoint-side for credential use anomalies that follow appliance compromise.
// Hunt 1: Suspicious process execution and file writes reported by NetScaler syslog forwarding
Syslog
| where TimeGenerated > ago(14d)
| where Computer has_any ("netscaler", "ns", "adc") or Facility =~ "local0"
| where SyslogMessage has_any ("/netscaler/portal/", "/var/vpn/", "/var/netscaler/gui/", "crontab", "rc.conf")
or SyslogMessage has_any ("/bin/sh", "/bin/bash", "curl ", "wget ", "perl -e", "base64 -d")
| project TimeGenerated, Computer, ProcessName, SyslogMessage, SeverityLevel
| order by TimeGenerated desc;
// Hunt 2: Anomalous outbound connections from appliance IPs (via CEF/network device logs)
let NetScalerIPs = dynamic(["10.0.0.0/8"]); // Replace with your appliance management/VIP subnets or specific IPs
CommonSecurityLog
| where TimeGenerated > ago(14d)
| where SourceIP in~ (NetScalerIPs) or DeviceProduct has "NetScaler"
| where DestinationPort in (443, 80, 8080, 53)
| where DestinationIP !in~ (NetScalerIPs)
| summarize ConnectionCount = count(), DistinctDestinations = dcount(DestinationIP) by SourceIP, DestinationIP, DestinationPort, bin(TimeGenerated, 1h)
| where DistinctDestinations > 20 or ConnectionCount > 500
| order by ConnectionCount desc;
// Hunt 3: Post-compromise identity signal — VPN session anomalies following appliance exploitation window
SigninLogs
| where TimeGenerated > ago(14d)
| where AppDisplayName has_any ("NetScaler", "Citrix", "Gateway", "VPN")
| summarize Sessions = count(), DistinctIPs = dcount(IPAddress), IPs = make_set(IPAddress) by UserPrincipalName, bin(TimeGenerated, 1h)
| where DistinctIPs > 3
| order by DistinctIPs desc;
Velociraptor VQL — Appliance Forensic Hunt
Where you have shell access or an acquisition path to NetScaler filesystems (or via a forensic image of the appliance), hunt for staged webshells and persistence artifacts.
-- NetScaler compromise hunt: webshells, recent web-dir writes, and persistence artifacts
-- Run against appliance filesystem acquisition or mounted forensic image
SELECT FullPath, Size, Mtime, Ctime
FROM glob(globs=[
'/netscaler/portal/**/*.php',
'/netscaler/portal/**/*.pl',
'/var/vpn/**/*.php',
'/var/netscaler/gui/**/*.php',
'/netscaler/ns_gui/**/*.cgi'
])
WHERE Mtime > now() - 60*86400 -- files modified in last 60 days
ORDER BY Mtime DESC
-- Network state review: unexpected listeners and outbound sessions
SELECT Pid, Name, LocalAddress, LocalPort, RemoteAddress, RemotePort, State
FROM netstat()
WHERE State =~ 'ESTABLISHED|LISTEN'
AND NOT RemoteAddress =~ '^(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.|127\.)'
ORDER BY RemotePort
Verification and Hardening Script (Bash — NetScaler Shell)
Run from the NetScaler shell (drop to shell from the CLI with shell) to verify build, hunt for staged artifacts, and audit persistence mechanisms. This does not replace patching — it supports your compromise assessment.
#!/bin/bash
# NetScaler CVE-2026-88771 / CVE-2026-88772 compromise assessment script
# Run on the appliance shell. Capture output to a file for IR evidence.
echo "=== [1] Current build version — compare against Citrix fixed builds ==="
show version 2>/dev/null || nsconmsg -d version 2>/dev/null || cat /flash/nsconfig/version 2>/dev/null
echo "=== [2] Recently modified files in web-accessible directories ==="
find /netscaler/portal /var/vpn /var/netscaler/gui /netscaler/ns_gui -type f \( -name "*.php" -o -name "*.pl" -o -name "*.cgi" -o -name "*.sh" \) -mtime -60 -exec ls -la {} \; 2>/dev/null
echo "=== [3] Cron and startup persistence audit ==="
cat /etc/crontab 2>/dev/null
ls -la /var/cron/tabs/ 2>/dev/null
ls -la /etc/rc.d/ 2>/dev/null | head -50
grep -r "" /flash/nsconfig/rc.conf 2>/dev/null
echo "=== [4] Unauthorized local accounts and SSH keys ==="
cat /etc/passwd | grep -v "nologin\|false"
find / -name "authorized_keys" -mtime -60 2>/dev/null -exec ls -la {} \;
echo "=== [5] Established outbound connections from appliance ==="
netstat -an | grep ESTABLISHED | grep -v "127.0.0.1\|::1"
echo "=== [6] Suspicious processes (shells under web service context) ==="
ps aux | grep -E "httpd|nshttpd|nginx" | grep -E "sh|bash|perl|python|curl|wget|nc"
echo "=== [7] Access log review: anomalous request patterns ==="
tail -5000 /var/log/httpaccess.log 2>/dev/null | grep -iE "\.php|\.cgi|cmd=|exec|eval|base64" | tail -50
echo "=== Assessment complete. Preserve this output before patching. ==="
Critical sequencing note: Collect forensic evidence before patching and before rebooting. Firmware updates and reboots destroy memory-resident implants and may overwrite staged artifacts. If you find indicators of compromise, preserve the filesystem and engage your IR retainer before remediation.
Remediation
- Patch immediately. Apply the fixed NetScaler ADC and Gateway builds published in the Citrix security bulletin covering CVE-2026-88771 and CVE-2026-88772. Pull the exact fixed version numbers for your release train directly from the official advisory: https://support.citrix.com (Citrix Security Bulletins) — verify both CVEs are addressed by the build you deploy, as separate fixes sometimes land in different builds.
- Assume pre-patch compromise. Patching closes the door; it does not remove anyone already inside. Complete the hunting steps above on every appliance that was internet-exposed and unpatched during the exploitation window. Look for webshells, rogue cron entries, new local accounts, and unauthorized SSH keys.
- Reset credentials if compromise is suspected or confirmed. This includes: all AD/LDAP service accounts used by the appliance for bind operations, local appliance admin accounts, any certificates/keys stored on the device, and — critically — user credentials that transited the gateway during the exposure window. Force password resets and revoke active sessions and tokens.
- Reduce the attack surface permanently. Restrict NetScaler management interface (NSIP) access to a dedicated management network — it must never be internet-reachable. If your gateway virtual servers must be public, place them behind a WAF and enforce strict egress filtering so the appliance cannot initiate arbitrary outbound connections.
- Kill sessions post-patch. After applying fixed builds, terminate all active ICA/VPN sessions (
kill icaconnection -all/ equivalent for your build) and invalidate authentication tokens to force re-authentication through the patched code path. - Monitor CISA KEV. Given confirmed in-the-wild exploitation, expect these CVEs to be added to the CISA Known Exploited Vulnerabilities catalog. Federal civilian agencies will have a binding remediation deadline; private organizations should adopt the same deadline as internal SLA.
- Review the Unit 42 brief and IOCs. Incorporate published indicators from the source threat brief into your SIEM watchlists: https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/
The Bottom Line
Two NetScaler zero days, confirmed exploitation, unpatched devices actively targeted — this is the exact threat profile that has preceded some of the most damaging intrusions of the past several years. The organizations that come out of this clean will be the ones that do three things in order: hunt first, patch fast, and rotate credentials without hesitation. If your NetScaler was internet-facing and unpatched this week, you are not doing vulnerability management anymore — you are doing incident response. Act accordingly.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.