Citrix NetScaler CVE-2026-88771 now under mass attack
Attacks on unpatched Citrix NetScaler ADC and Gateway appliances have moved from a small number of targeted intrusions to broad, opportunistic exploitation across the internet. The change came after a root-cause analysis and a proof-of-concept (PoC) exploit for CVE-2026-88771 were published.
The flaw can be exploited remotely on unpatched devices running the default configuration. Researchers now say most exposed appliances have not yet been updated.
A zero-day confirmed by Citrix
Reports that attackers were exploiting an unknown NetScaler flaw began circulating late last week. Citrix confirmed them when it released a security advisory alongside patches for eight vulnerabilities rated critical or high risk.
Two of those flaws, CVE-2026-88771 and CVE-2026-88772, had been exploited as zero-days before fixes were available.
Citrix also released a detection script that customers can run to look for signs of compromise. The company warned that the script "might fail to identify actual compromises", because attackers often change their tactics, techniques, and procedures (TTPs) and the infrastructure they use.
Since the advisory, several security companies and independent researchers have published their own findings.
An early attempt caught by a sensor
GreyNoise, a threat intelligence company that runs a large network of deception sensors to observe attacker behavior, says it recorded a zero-day exploitation attempt against a Citrix NetScaler Gateway on September 24. That was more than three days before the flaw was publicly disclosed.
The attack did not succeed. "Though the adversary was unsuccessful in gaining a foothold on the targeted Swarm sensor, their post-exploitation playbook was revealed," the company said.
According to GreyNoise, the attacker tried to gain administrator access and plant a webshell (a backdoor) behind a URL disguised as a stylesheet. The attacker also tried to erase traces from the logs and restart the server.
Exploitation within minutes of the PoC
The situation changed once watchTowr Labs released a PoC for CVE-2026-88771. Xavier Bellekens, CEO of cyber deception and threat intelligence firm Lupovis, told Help Net Security that the company's sensors began logging live exploitation attempts against NetScaler within minutes of the release.
These attempts were not aimed at specific victims. They were scans across the internet for exposed, unpatched appliances. "If you run NetScaler and you haven't patched, assume you are already being probed," Bellekens said.
The attackers rely on log poisoning. The stolen data is sent to a server hosted by Hetzner at 138.199.200.90.
Bellekens recommends that organizations search for POST requests to /nf/auth/doAuthentication.do whose body contains the string "pitboss PPE unexpectedly died NSPPE". Defenders should also check DNS logs for outbound lookups ending in instances.httpworkbench.com. Such lookups indicate that a host in their environment has already been hit.
CERT-EU, the cybersecurity service for the institutions, bodies and agencies of the European Union, has also published technical details and threat-hunting guidance. The advice draws on the investigation it opened after first hearing rumors of exploitation.
Tens of thousands of exposed appliances
Censys, which operates an internet-scanning platform, says it currently sees around 42,000 internet-facing hosts running NetScaler ADC or NetScaler Gateway. It cannot tell from its scans whether these hosts are vulnerable or already compromised.
"The United States accounts for 13,549 hosts (32%), followed by Germany at 5,678 (13%), then the Netherlands, United Kingdom, and Switzerland at roughly 4% each," the company said.
Censys added that Microsoft hosts 4,254 of these systems (10%) and Amazon 3,013 (7%). This matches NetScaler VPX virtual appliances deployed in public cloud environments. More than three quarters of the hosts sit outside the ten largest networks, spread across enterprise and telecom address space.
Security researcher Kevin Beaumont said his firmware-version scanning shows fewer than 10% of exposed hosts are currently patched. He is tracking more than 100 victim organizations and noted that "each one has a unique webshell which can't be scanned for remotely unless you're the attacker." Beaumont believes the original attackers were after espionage.
No public PoC exists yet for CVE-2026-88772, the second flaw the initial attackers exploited.
Why It Matters
For NetScaler administrators, the practical advice is simple. Patching alone is no longer enough. The GreyNoise sighting shows exploitation began days before disclosure. Beaumont's comment about unique webshells suggests that a device can be updated and still contain a backdoor left behind earlier. Organizations with exposed appliances should treat them as possibly compromised and hunt for the indicators shared by Lupovis and CERT-EU. Citrix's own warning about its detection script is another reason not to treat a clean scan result as proof.
The case follows a familiar pattern for edge devices. Capable attackers quietly use a flaw first, then a public PoC opens the door to mass scanning within hours or even minutes. Recent exploitation of the Check Point VPN flaw CVE-2026-85102 shows that remote access gateways remain a favorite entry point. Espionage-driven campaigns against internet-facing software, such as the recent Roundcube SQL injection attacks, point in the same direction.
It is worth watching whether a PoC appears for CVE-2026-88772, which could start a second wave of attacks. It is also worth watching whether financially motivated groups follow the scanners, as happened when a TeamCity flaw was picked up by ransomware gangs. With fewer than 10% of exposed hosts patched, attackers still have plenty of targets.
