Back to Newsroom
Threat Intel

Citrix NetScaler Flaw Exploited to Plant Superuser Backdoors and CSS-Disguised Web Shells

A critical pre-auth command injection bug in Citrix NetScaler ADC and Gateway is being actively exploited to create hidden superuser accounts, steal configuration data, and plant web shells disguised as CSS files.

Citrix NetScaler Flaw Exploited to Plant Superuser Backdoors and CSS-Disguised Web Shells

Attackers are actively exploiting a critical command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway, using it to plant hidden administrator accounts, exfiltrate device configuration, and deploy web shells disguised as ordinary CSS files.

What happened

The vulnerability, tracked as CVE-2026-88771 (CVSS 9.5), is an improper input validation flaw that lets an unauthenticated attacker run arbitrary commands on vulnerable NetScaler appliances before any login is required. It was disclosed alongside a second flaw, CVE-2026-88772, after a national cyber security authority warned organizations to take affected appliances offline due to active exploitation in the wild.

Threat hunters tracking the campaign across multiple customer environments found a consistent fingerprint: authentication attempts using attacker-controlled usernames built around variations of "pitboss" and "NSPPE" — strings tied specifically to exploitation of CVE-2026-88771.

Once inside, the attackers don't stop at proof-of-concept access. Observed post-exploitation activity includes:

  • Fetching second-stage payloads from external servers via curl or wget, including a Python reverse-shell script and a Perl-based post-exploitation tool.
  • Creating a hidden superuser account by rewriting the appliance's configuration file, giving attackers persistent privileged access that survives a simple patch.
  • Stealing the full NetScaler configuration by archiving it, uploading it to an external server, then deleting the archive and erasing traces to limit forensic recovery.
  • Planting a PHP web shell and changing shell permissions to enable remote command execution, then disguising the web shell's URL to resemble legitimate NetScaler CSS resource paths — making it blend into normal appliance traffic.
  • Killing competing processes tied to other implants, suggesting multiple threat actors may be fighting over the same compromised devices.

The disclosure lands a day after separate research tied a related flaw, CVE-2026-88772, to attacks against dozens of organizations using similarly disguised PHP web shells and a custom Python tunneling tool.

Why it matters

NetScaler ADC and Gateway devices sit at the network edge, often fronting VPNs and internal applications — exactly why they're a favorite target. A pre-authentication command injection flaw on a device like this isn't just a foothold: it's a direct path to credential theft, lateral movement, and long-term persistence that can survive a reboot or even a firmware update, since the attacker plants their own admin account and configuration changes rather than relying on the original exploit staying open.

The disguised web shell technique is particularly dangerous because it's built to pass a casual review — a URL that looks like a CSS file won't raise flags in routine log scans, and the self-deleting archive step is designed specifically to frustrate incident responders trying to establish what was taken.

What to do

  • Patch immediately. Apply the vendor fixes for CVE-2026-88771 and CVE-2026-88772 on every internet-facing NetScaler ADC and Gateway appliance — don't wait for a maintenance window given the active exploitation.
  • Hunt for the indicators, not just the patch status: look for authentication logs containing "pitboss" or "NSPPE"-style usernames, unexpected local accounts with superuser roles, and any files under the NetScaler logon directory that don't match a known-good baseline.
  • Review outbound connections from NetScaler appliances for unexpected traffic to external IPs, especially over port 443 or 9000/9090 to unfamiliar hosts.
  • Assume compromise, not just vulnerability, on any appliance that was internet-facing and unpatched during the exploitation window — a clean patch doesn't remove an attacker-created account or an already-planted web shell. Rotate credentials and configuration secrets stored on the device.
  • Treat this as a reminder, not a one-off: edge devices like NetScaler deserve the same asset inventory and patch-SLA discipline as any internet-facing server, because attackers are clearly watching for exactly this class of flaw.
SHARE