Citrix NetScaler Under Active Attack: Patch Now to Avoid Web Shells and Superuser Backdoors
Security researchers at LevelBlue have observed active exploitation of a critical flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, tracked as CVE-2026-88771 (CVSS 9.5). The vulnerability allows an unauthenticated attacker to execute arbitrary commands on vulnerable devices, and has been linked to a second flaw, CVE-2026-88772. The Dutch National Cyber Security Centre reportedly warned organisations to shut down affected appliances due to active exploitation in the wild.
LevelBlue found attacker-controlled usernames referencing internal NetScaler process names during exploitation attempts, along with evidence that attackers are going beyond simple testing. In many cases, attackers used tools like curl or wget to fetch additional malicious payloads, including scripts that set up reverse shells, terminate legitimate system processes, create privileged superuser accounts, and deploy web shells disguised to look like harmless CSS style files. Other activity involved collecting and exfiltrating NetScaler configuration data, which can contain sensitive credentials and network details.
At this stage, it is not known who is behind the attacks. However, the scale and sophistication of the observed activity suggest a well-resourced threat actor actively targeting internet-facing NetScaler devices before organisations can patch.