An attacker was already trying to exploit Citrix's newest NetScaler zero-day more than three days before the world knew it existed, and tried to leave behind a hidden webshell disguised as a stylesheet. That is the picture from GreyNoise's original report: its sensor network caught the attempt on September 24, 2026, against a NetScaler Gateway sensor run by a participant in its Project Swarm program.
The flaw, CVE-2026-88771, was publicly disclosed on September 27, the day CISA added it and a second NetScaler bug to its Known Exploited Vulnerabilities catalog, as IntelFusions reported. GreyNoise's timeline shows the CVE ID was reserved on September 10 and exploitation attempts began at 07:32 UTC on September 24, roughly 80 hours before public disclosure at 15:51 UTC on September 27.
Caught by behavior, not by signature
No CVE-specific detection existed yet, so GreyNoise's generic behavioral rules did the work. The source IP, 149[.]104[.]78[.]141, was labelled suspicious within seconds for crawling the Citrix gateway login panel, and malicious four seconds later. The tags that fired included a generic ${IFS} remote code execution attempt and GreyNoise's CitrixBleed 2 (CVE-2025-5777) tag. When GreyNoise deployed a dedicated CVE-2026-88771 tag on September 27 and hunted back through its stored traffic, it matched only that one IP's three sessions on September 24, all within about a second.
GreyNoise says it is withholding the full exploitation chain for now, and that patches are available.
A webshell hiding as a stylesheet
The attack failed against the sensor, but it exposed what the attacker meant to do next. According to GreyNoise, the commands tried to:
- set the setuid and setgid bits on /bin/sh (chmod 6555) to obtain a root shell;
- write a password-protected PHP webshell to the hidden file /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver;
- edit /etc/httpd.conf so the web server treats that dot file as PHP, and add an Alias and an AliasMatch so requests for receiver.min.css, or variants such as receiver.min.<hex>.css, are routed to the webshell;
- switch the PHP engine on and signal the web server process to restart.
The webshell only runs commands when a request carries a secret value in a CsrfToken cookie, and it reads the command itself from a second cookie named NSC_TASS. GreyNoise suggests this design may be meant to keep the attacker's commands out of web logs.
Patch, then hunt for .ctxs.receiver
Patching closes the door but does not evict anyone who got in earlier. Palo Alto Networks' Unit 42 has counted about 50,000 exposed NetScaler instances, as covered in our follow-up, and exploitation was under way at least from September 24. Based on the playbook GreyNoise observed, NetScaler owners should check for:
- a file named .ctxs.receiver under /var/netscaler/logon/LogonPoint/custom/;
- Alias or AliasMatch lines in /etc/httpd.conf pointing receiver.min.css paths at that file, or php_flag engine switched on;
- setuid or setgid bits set on /bin/sh;
- connections from 149[.]104[.]78[.]141;
- a file matching the webshell's SHA-256 hash, 6f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7.
GreyNoise cautions that other indicators are being shared at a higher Traffic Light Protocol level, that no indicator set should be treated as complete, and that attackers can poison server logs with varied payloads during exploitation. One IP and one hash are a starting point for a hunt, not a clean bill of health.
The uncomfortable lesson for anyone who patched on disclosure day is that the window of exposure opened days earlier, and at least one attacker arrived with a persistence plan already written.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.