NetScaler attackers try a new trick to grab device configs

Published

Attackers going after Citrix NetScaler appliances have started using a new version of their log-poisoning trick, and one of the commands they tried would copy the appliance's entire configuration into a web folder that anyone could download. That finding comes from the original report by Sygnia researchers Omer Kidron, Roey Bartov, Josh Geise and Avishay Asido, published September 30, 2026.

The target is CVE-2026-88771, the pre-authentication command injection bug Citrix fixed on September 27 alongside CVE-2026-88772. Sygnia lists both at 9.5 on CVSS v4, and both are being exploited, as IntelFusions reported when CISA listed them. Sygnia stresses that CVE-2026-88771 affects every customer-managed NetScaler ADC and Gateway deployment without needing any optional feature switched on.

A fake crash message that runs commands

The bug works by getting attacker text written into NetScaler's logs dressed up as a Packet Processing Engine failure message. A legitimate maintenance script, /netscaler/ns_monuploadd_err.pl, may later read the poisoned line and pass it to a shell, so the embedded command runs as root. Because that processing can be delayed, Sygnia says defenders should correlate any suspicious request with system activity for at least the following 24 hours.

Earlier attacks used a fake "missed too many heartbeats" message to pull Base64 payloads back out of the HTTP logs, including one that tried to plant a hidden PHP web shell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver and reconfigure Apache to serve it behind CSS-looking URLs. GreyNoise caught a similar stylesheet-disguised attempt days before disclosure.

The new variant surfaced on September 29

On September 29, Sygnia's telemetry turned up a different fake message, "pitboss PPE unexpectedly died NSPPE", carrying three attempted commands: one copying /flash/nsconfig/ns.conf to /var/netscaler/logon/insight-new.js, one fetching a Perl script from 64[.]94[.]85[.]67 on port 443 and piping it straight to perl, and a run of whoami checks. Sygnia is careful to say the log records prove the commands reached the vulnerable path, not that each one actually executed.

The firm also describes an incident response case from before Citrix's fix, in which an attacker ran commands on a NetScaler already on the newest available build and then reached virtualization and identity systems. Sygnia did not establish how that attacker got in and is not tying it to either new CVE, but says it shows how far a compromised edge appliance can reach.

Patch every node, then hunt as if you were hit

The fixed builds are 14.1-73.37 and 13.1-64.23 or later, with matching FIPS and NDcPP releases; Sygnia notes that 13.1-64.24 is needed where show ns variable returns configured variables. Its central point is that patching closes the hole but removes nothing already planted. It recommends preserving logs before any rebuild, reviewing at least 30 days of raw NetScaler logs, searching ns.log for "pitboss PPE" alongside "unexpectedly died" or "missed too many heartbeats", checking httpd.conf files for AddHandler lines that make .sig, .css or .ico files run as PHP, and investigating any /bin/sh set to mode 6555. If web shells turn up, terminate all Citrix sessions, because deleting the shell does not end sessions the attacker already holds.

Indicators Sygnia rates high confidence (defanged): 64[.]94[.]85[.]67, 77[.]83[.]199[.]39, 45[.]76[.]34[.]141 and 170[.]64[.]176[.]26; file update_c08937.pl; SHA-256 5ea5ea61e9062822bee3f66ef5ff47c217178d9e31936ad6daf10c5dfae44d12. Sygnia says these are investigation-derived and should be validated against local context before blocking.

Two days after disclosure, attackers were already reworking the same trick. Any NetScaler that sat unpatched this week deserves a compromise hunt, not just an update.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions