Threat Intelligence

Citrix NetScaler Under Active Attack: Patch Now to Avoid Web Shells and Superuser Backdoors

The Hacker News · 1 Oct 2026
Key Takeaway If your business uses Citrix NetScaler ADC or Gateway appliances, apply vendor patches immediately and check for unfamiliar admin accounts or unexpected files on the device.

Security researchers at LevelBlue have observed active exploitation of a critical flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, tracked as CVE-2026-88771 (CVSS 9.5). The vulnerability allows an unauthenticated attacker to execute arbitrary commands on vulnerable devices, and has been linked to a second flaw, CVE-2026-88772. The Dutch National Cyber Security Centre reportedly warned organisations to shut down affected appliances due to active exploitation in the wild.

LevelBlue found attacker-controlled usernames referencing internal NetScaler process names during exploitation attempts, along with evidence that attackers are going beyond simple testing. In many cases, attackers used tools like curl or wget to fetch additional malicious payloads, including scripts that set up reverse shells, terminate legitimate system processes, create privileged superuser accounts, and deploy web shells disguised to look like harmless CSS style files. Other activity involved collecting and exfiltrating NetScaler configuration data, which can contain sensitive credentials and network details.

At this stage, it is not known who is behind the attacks. However, the scale and sophistication of the observed activity suggest a well-resourced threat actor actively targeting internet-facing NetScaler devices before organisations can patch.

Citrix NetScaler vulnerability exploitation web shell

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.