Threat actors are exploiting a critical pre-authentication command injection flaw in Citrix NetScaler ADC and NetScaler Gateway to install web shells and steal configuration data, according to new research from LevelBlue's Threat Hunt Operations & Research (THOR) team. The security team analyzed exploitation activity across multiple customer environments and identified malicious authentication events containing attacker-controlled usernames crafted to weaponize the vulnerability. The flaw, tracked as CVE-2026-88771, carries a CVSS severity score of 9.5 and allows unauthenticated attackers to execute arbitrary commands due to improper input validation.

LevelBlue's investigation revealed consistent patterns in the attacks, with malicious authentication data frequently containing variations of the pitboss and NSPPE strings linked to CVE-2026-88771 exploitation. Additional attack attempts used curl or wget commands to download payloads from external servers or extract NetScaler configuration data from three identified command-and-control locations: 64.94.85[.]67:443/update_c08937.pl, 31.56.197[.]72:9090/lula, and 23.27.143[.]20:9000/main.py. Among the second-stage payloads, researchers documented a Python script called main.py designed to create a reverse shell to 45.141.21[.]130 over TCP port 443, while also searching for processes associated with "/var/python/bin/customsnmpd" and terminating them with a kill -9 command. Another payload, the Perl script update_c08937.pl, demonstrated extensive post-exploitation capabilities including modifying ns.conf to create a local account named sec_monitor with superuser privileges, archiving the nsconfig directory into a compressed file that gets uploaded to an attacker-controlled server before deleting itself to erase forensic evidence, changing permissions on /bin/sh to 6555, and deploying a PHP web shell at a specific path for remote command execution and file transfers.

According to LevelBlue, the observed commands "demonstrate activity extending beyond basic vulnerability validation," including payload retrieval and execution as well as collection and staging of NetScaler configuration data. The researchers noted that while some attempts used commands such as whoami to test command execution, others attempted to retrieve additional payloads, collect NetScaler configuration data, establish reverse shells, create privileged accounts, and deploy web shells. The security team also confirmed that attackers modified httpd.conf files to enable PHP execution and mapped web shells to URLs that resemble legitimate NetScaler CSS resources, a finding that corroborates activity previously observed by GreyNoise.

The attacks follow last week's disclosure of CVE-2026-88771 and CVE-2026-88772 after the Dutch National Cyber Security Centre (NCSC-NL) reportedly sent pre-notifications to organizations in the Netherlands urging them to shut down their appliances due to active exploitation. A separate disclosure from Mandiant Consulting and Google Threat Intelligence Group revealed that dozens of organizations have been compromised through attacks exploiting CVE-2026-88772 to deliver PHP web shells like WHIPSHOT and a Python tunneler dubbed SLAPSHOT. As of now, there are no details about the identity or motivation of the threat actors behind these campaigns. The multi-stage nature of the attacks—moving rapidly from initial exploitation to credential creation, data theft, and persistent access—underscores the speed at which adversaries can pivot from reconnaissance to full compromise once a vulnerability is weaponized. Organizations running affected NetScaler products face immediate risk of unauthorized access, configuration theft, and establishment of persistent backdoors that survive routine security checks. The deployment of defensive infrastructure will likely require not just patching but comprehensive forensic examination to ensure attackers haven't already established covert access channels.