Live
Abstract illustration: a bright new top layer over older layers that still hold glowing implants
Privacy & Security

Patching Citrix NetScaler Won’t Remove the Web Shells Already Inside

In August 2023, the Dutch security firm Fox-IT counted roughly 2,000 Citrix NetScaler appliances carrying web shells from a mass-exploitation campaign. About 69 percent of them were no longer vulnerable to the bug that let attackers in. Their owners had patched. The backdoors stayed.

Defenders are about to relearn that lesson. Two new remote-code-execution flaws in NetScaler ADC and NetScaler Gateway, CVE-2026-88771 and CVE-2026-88772, were exploited for weeks before Citrix shipped a fix, and the guidance from the people investigating them is unambiguous: updating closes the door, but it doesn’t remove anyone already inside.

What happened

Citrix released patches on Sunday, Sept. 27, for eight vulnerabilities numbered CVE-2026-88771 through -88778, and confirmed that “exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed,” Help Net Security reported. Both exploited flaws carry a CVSS score of 9.5, according to Tenable. The first is an input-validation bug that works against default configurations without authentication; the second is a memory overflow reachable when DTLS is enabled, which is the default on VPN virtual servers, per The Hacker News. Fixed builds are 14.1-73.37 and 13.1-64.23, plus FIPS and NDcPP variants. Versions 12.1 and 13.0 are end-of-life and get nothing.

The same day, CISA added both CVEs to its Known Exploited Vulnerabilities catalog and ordered federal civilian agencies to patch by Wednesday, Sept. 30, and to run forensic triage for signs of compromise. The Dutch National Cyber Security Center, whose warnings to IT suppliers first surfaced on Reddit on Friday, Sept. 25, said the first flaw “gives attackers full control of the gateway, providing direct access to the internal corporate network behind it.”

Nobody has formally named the attackers. Mandiant and Google Threat Intelligence Group, in a Sept. 29 technical write-up, traced the campaign to at least early September and confirmed victims in government, financial services, technology, education and legal and professional services across North America and Europe, without attribution. Security researcher Kevin Beaumont’s read, quoted by Help Net Security, is that the attackers were “probably nation state aligned as well resourced, espionage rather than teens.” Treat that as informed speculation, not a finding.

Why a patch isn’t a cleanup

Concentric rectangular frames, the outermost freshly outlined in green, with a glowing blue diamond implant still lodged near the center and sending thin tendrils outward through the inner frames.
Illustration: prompt/power

Mandiant’s report describes what the intruders left behind. A PHP web shell it calls WHIPSHOT answers requests with an HTTP 404 while tunnelling traffic in the response body. A Python tunneller, SLAPSHOT, bridges into the internal network. The attackers edited the appliance’s web-server configuration so that files ending in .deb or .sig would execute as PHP, disguised requests as fetches of .ico icon files, and set the setuid bit on /bin/sh for root persistence across reboots. None of that is undone by installing a new firmware build.

There’s also a clock problem. Beaumont pointed out, in Help Net Security’s account, that Citrix’s detection script in NetScaler Console only works if the device’s logs haven’t rotated since the attack, and with activity going back weeks, they probably have.

Hunt, don’t just patch

Drawn from Mandiant’s guidance and the Dutch NCSC’s advice as reported by Help Net Security:

  1. Preserve evidence before you upgrade. NCSC-NL advises backing up device memory and log files going back at least a month before installing updates.
  2. Read the web-server config. Look in /etc/httpd.conf for unexpected PHP handler, php_flag or AliasMatch lines, the mechanism Mandiant found mapping .deb, .sig and .ico paths to PHP.
  3. Check the VPN plugin folders. Files under /var/netscaler/gui/vpn/scripts/ that are actually PHP or plain text, or contain eval or base64_decode, are suspect.
  4. Look for the tunnel’s footprints. Files named /tmp/.uxdport or /tmp/.uxdlock, and Python processes referencing them, match SLAPSHOT.
  5. Check /bin/sh. A setuid bit (-rwsr-xr-x) is a red flag.
  6. Mine access logs and your SIEM. Mandiant flags 404 responses for /vpn/media/ icons that are oddly large; Beaumont suggests searching for pitboss log lines followed by IFS or b64decode.
  7. Assume credentials are gone. After patching, Mandiant recommends rotating appliance secrets plus LDAP, RADIUS and SSH keys, killing active admin, VPN and ICA sessions, and restricting outbound traffic. Blocking UDP/443 or disabling DTLS cuts off the second flaw’s delivery path where that’s workable.

Our read on why this is the enterprise story of the week: a NetScaler Gateway is the box that decides who gets onto the corporate network, and Tenable counted 13 NetScaler entries in CISA’s exploited-vulnerabilities catalog as of Sept. 27. Fox-IT’s 2023 numbers are the uncomfortable precedent. Most of those 2,000 backdoored machines had been patched, by owners who presumably considered the job finished.

Sources

// Columnist, Security & Privacy
Oman Hassan

Oman Hassan covers cybersecurity and privacy for prompt/power: breaches, exploits, surveillance and the policy that follows them. He assumes the password is "password" until proven otherwise.

Latest from prompt/power

  1. Gemini’s Free Tier Shrinks Oct. 9: What You Keep and What Costs ExtraOct 5
  2. How to Read an AI Company’s S-1: The 7 Numbers That MatterOct 5
  3. OpenAI’s Safety Lead Quit Over Culture. California’s AG Was Already InOct 5
  4. When an AI Agent Breaks In, Who Answers for It?Oct 5
  5. The New AI Models Don’t Talk. They Decide.Oct 5

Leave a Reply

Your email address will not be published. Required fields are marked *