The NetScaler Payloads That Create Their Own Superusers and Hide in CSS URLs
LevelBlue's Threat Hunt Operations team documented what actually ran on compromised NetScaler appliances after CVE-2026-88771 and CVE-2026-88772 were exploited: a Perl script that creates a
TL;DR
- On October 1, 2026, LevelBlue's Threat Hunt Operations & Research (THOR) team published its analysis of what ran on NetScaler appliances after CVE-2026-88771 and CVE-2026-88772 were exploited: payload retrieval, configuration exfiltration, reverse shells, privileged account creation, and web shell deployment.
- The two vulnerabilities are zero-days exploited in the wild before a fix existed: CVE-2026-88771 is a 9.5 pre-authentication command injection that affects every NetScaler ADC and Gateway deployment, including the default configuration; CVE-2026-88772 is a 9.5 memory overflow reachable through DTLS, which is enabled by default on VPN virtual servers. The campaign surfaced September 26 with a Dutch NCSC pre-notification urging operators to shut appliances down; Citrix published fixed builds on September 27, 2026, and CISA added both CVEs to its Known Exploited Vulnerabilities catalog the same day.
- The post-exploitation payloads are the part that should change your mental model: a Perl script creates a local superuser named
sec_monitor, ships/flash/nsconfigto an external host, deploys a PHP web shell disguised as a CSS-like URL, and then deletes its own archive — explicitly to reduce the forensic footprint. - The operational consequence: capture evidence before you run the upgrade, because the patch fixes the door and does nothing about the people already inside.

A payload built to delete its own evidence
The most instructive detail in LevelBlue's report is not the exploit — it is the second stage. The Perl payload update_c08937.pl does four things in sequence: it modifies /flash/nsconfig/ns.conf to create a local account named sec_monitor and grant it the superuser role; it archives the whole /flash/nsconfig directory into /tmp/update_result_3567cs.tgz and uploads the archive — containing the appliance configuration — to 64.94.85[.]67:443; it changes the permissions of /bin/sh to 6555 and deploys a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal for remote command execution plus file upload and download; and finally it deletes the archive and erases itself.
That last step deserves a full sentence. The script is written to shrink the forensic footprint on disk by design. Whoever built it assumes the defender will look at the appliance after the fact, and wants the story to be as short as possible when they do.
LevelBlue's summary of the whole pattern is tighter than any paraphrase: "While some attempts used commands such as whoami to test command execution, others attempted to retrieve additional payloads, collect NetScaler configuration data, establish reverse shells, create privileged accounts, and deploy web shells." That is an intrusion playbook stated in one sentence, and every item in it is a permanent capability, not a beachhead.

The two zero-days behind the campaign
The campaign rides on two flaws the vendor itself confirmed as exploited in the wild. CVE-2026-88771 is improper input validation that lets an unauthenticated attacker run arbitrary commands on the appliance — and the precondition is every deployment, default configuration included. No extra feature, no special virtual server type, no configuration choice triggers it: the bulletin states that all NetScaler ADC and Gateway deployments are impacted by one or more of the eight vulnerabilities it fixes, and that 88771 alone covers the whole fleet.
CVE-2026-88772 is a memory overflow reachable over DTLS. The reason it matters even though it has a precondition is that the precondition is the default: DTLS is enabled by default on VPN virtual servers, which is precisely the configuration that makes a NetScaler Gateway a VPN gateway. Mandiant and Google Threat Intelligence Group documented the exploitation chain: bypassing authentication and triggering an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access on the underlying FreeBSD platform.
The timeline matters as much as the mechanics. Evidence of exploitation surfaced on September 26, 2026, when administrators reported being told by suppliers and security teams to shut appliances down, following a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL). The Citrix bulletin landed September 27. CISA added both CVEs to the Known Exploited Vulnerabilities catalog the same day. This is the zero-day cadence operating exactly as designed: warn the operators who can act, publish the fix, and let the public catalog catch up within hours.

What the kit tells us about the operators
Combine LevelBlue's telemetry with Mandiant's toolkit analysis and a consistent picture emerges: the actors are not scanning for a shell and moving on. They want the appliance's configuration, a persistent superuser identity that survives reboots, and a web shell that looks like a stylesheet. The PHP web shell placed at LogonPoint/.local_journal is deliberately mapped to URLs that resemble legitimate NetScaler CSS resources — an approach corroborated by GreyNoise's observations. It is evasion designed for a device category that security teams monitor poorly, because most NetScaler deployments sit at the edge and log to themselves.
The second distinctive behavior is the pairing of tools. Mandiant described WHIPSHOT, a PHP web shell that disguises Base64-encoded command-and-control payloads inside native HTTP headers, alongside SLAPSHOT, a Python tunneler that proxies traffic into internal networks for reconnaissance and credential theft. In at least one observed intrusion, the actor routed traffic through that tunnel to conduct internal reconnaissance manually. That is not automation for its own sake; it is an operator who wants a stable channel into the internal network before doing anything noisy.
The response order that keeps evidence usable
Citrix, CISA, and watchTowr converge on the same uncomfortable sequence: do not just patch. CISA advises checking for compromise and preserving forensic evidence before updating, because the update itself can remove the evidence of a compromise that is already in place. watchTowr spells out the order: capture logs, a snapshot, a support bundle and a core dump from each exposed appliance before upgrading; run an IOC scan from the NetScaler Console Security Advisory page (version 14.1-73.36 or later, with telemetry enabled) or request the generic IOCs from Citrix Support; then install the fixed build — on 13.1, run show ns variable first, because 13.1-64.23 has a known cyclic-reboot issue during upgrade that 13.1-64.24 avoids.

The rest of the list is standard appliance-compromise hygiene with one NetScaler-specific twist: rotate passwords, secrets and certificates stored on or used through the appliance, forward NetScaler logs to an external SIEM, and keep management interfaces off the public internet. The twist is that Citrix's own IoC guidance carries an honest disclaimer — the indicators do not encompass all techniques, tactics and procedures, and may be of limited forensic value. A clean IOC scan is one data point among several.
Why an edge appliance deserves crown-jewel treatment
The uncomfortable truth of this campaign is that the exploited device is the appliance that sits between the office and every internal application, handling VPN, remote access, load balancing and authentication. A compromised NetScaler gives an attacker a foothold at the perimeter and a path to internal systems, and the post-exploitation kit is built to make that path permanent: a superuser account in the config, a web shell that looks like a CSS file, and a tunnel into the network.
This is the same management-plane argument we made about the NVIDIA Infrastructure Controller with hard-coded credentials: when the device at the edge becomes the trust boundary, the question stops being "is this product vulnerable" and becomes "can we detect and expel someone already inside." NetScaler post-exploitation now has a canonical answer to that question — the payloads are designed to make the second half as hard as possible. Evidence capture before upgrade is not bureaucracy; it is the only part of this response that still works after the attacker has cleaned up after themselves.

The pattern generalizes to every appliance class that combines remote access with local logging: preserve before you patch, treat a clean scan as one signal among others, and assume the payload that ran is smarter about its own footprint than your first forensic look. The fixed builds for CVE-2026-88771 through CVE-2026-88778 are published across 14.1-73.37 and 13.1-64.23 branches. The patch is the easy part of this incident — it always is. The hard part is the evidence you either captured before upgrading, or lost.
Sources
Source: Citrix NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 — community.citrix.com, 2026-09-27 (all CVE descriptions, fixed versions, DTLS preconditions and IoC guidance quoted verbatim; official bulletin CTX697096 on support.citrix.com). Source: Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs — thehackernews.com (LevelBlue THOR findings), 2026-10-01. Source: Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances — Mandiant / Google Threat Intelligence Group, cloud.google.com/blog, 2026-09-29. Source: CVE-2026-88771: Citrix NetScaler ADC & Gateway RCE zero-days — watchtowr.com/intelligence, 2026-09-28. Internal linkage: NVIDIA Infrastructure Controller hard-coded credentials. More security engineering analysis on neticslabs.com.
Source: LevelBlue THOR via The Hacker News, 2026-10-01; Citrix security bulletin, 2026-09-27. Captures: official Citrix NetScaler documentation (docs.netscaler.com) and official Mandiant/GTIG Google Cloud blog article, captured 2026-10-02.