Protect.Computer
NEWS

Citrix NetScaler Zero-Days Exploited to Drop Web Shells

· 1 min read · Network safety Got hacked
Citrix NetScaler Zero-Days Exploited to Drop Web Shells

Citrix has confirmed that two critical remote code execution (RCE) vulnerabilities in NetScaler — tracked as CVE-2026-88771 and CVE-2026-88772 — are being actively exploited in the wild. Security researchers have named the exploitation campaign “PitScaler.” Attackers who gain an initial foothold via either flaw are deploying custom web shells directly on exposed NetScaler appliances, installing tunneling malware to maintain persistent access, escalating to root privileges, and using the compromised gateway to steal credentials and move laterally into the victim organization’s internal network.

Citrix released security patches for both vulnerabilities and urged administrators to apply them immediately or take affected appliances offline until patching is complete. The dual-CVE nature of the campaign makes it particularly dangerous: even organizations that remediated one flaw may still be exposed through the other if both were not patched in the same maintenance window. NetScaler ADC and NetScaler Gateway deployments used as internet-facing VPN or load-balancing gateways are the primary target, as they offer attackers an initial entry point without requiring stolen credentials.

How to check if you’re affected

Affected products are Citrix NetScaler ADC and Citrix NetScaler Gateway on versions that have not yet received the September 2026 security updates addressing CVE-2026-88771 and CVE-2026-88772. Citrix’s advisory lists the exact affected versions and the patched builds. Indicators of compromise include unexpected web shell files in the NetScaler web root, outbound connections from the appliance to unfamiliar IP addresses, and new administrator accounts or SSH keys not created by your team. Any appliance exposed to the internet that has not been patched should be treated as potentially compromised until a full forensic review is completed.

Sources

Related reading