NEWS

Citrix NetScaler CVE-2026-88771 Exploitation Spawns Superuser Backdoor, CSS-Disguised Web Shell

LevelBlue found CVE-2026-88771 exploitation on Citrix NetScaler creating a sec_monitor superuser account and a PHP web shell mapped to CSS-like URLs.

Dylan H.

News Desk

October 5, 2026
9 min read
Citrix NetScaler CVE-2026-88771 Exploitation Spawns Superuser Backdoor, CSS-Disguised Web Shell

LevelBlue Maps Post-Exploitation Payloads Tied to Citrix NetScaler CVE-2026-88771

Researchers at LevelBlue's Threat Hunt Operations & Research (THOR) team have published a detailed breakdown of the second-stage payloads attackers are dropping after exploiting CVE-2026-88771, a critical pre-authentication command injection vulnerability (CVSS 9.5) in Citrix NetScaler ADC and NetScaler Gateway. Analyzing exploitation activity across multiple customer environments, LevelBlue found that attacker-controlled authentication data containing variations of the strings "pitboss" and "NSPPE" was the most consistent indicator tied to CVE-2026-88771 abuse. Once inside, attackers deployed a Python reverse shell (main.py) and a Perl script (update_c08937.pl) that creates a hidden superuser account, archives the appliance's configuration for exfiltration, and rewrites NetScaler's web server configuration to disguise a PHP web shell as a CSS stylesheet request — a technique engineered to blend malicious traffic into an appliance's normal web logs. The findings, reported by The Hacker News on October 1, 2026, add granular indicators of compromise to a vulnerability that CISA added to its Known Exploited Vulnerabilities catalog after the Dutch NCSC-NL pre-notified organizations in the Netherlands to shut down exposed appliances.


Incident Details

AttributeValue
CVE IDCVE-2026-88771
CVSS score9.5 (Critical)
Vulnerability typePre-authentication command injection / improper input validation (CWE-20)
Affected productsCitrix NetScaler ADC and NetScaler Gateway, default configuration
Companion flawCVE-2026-88772 (memory overflow, DTLS), disclosed the same day
DisclosedSeptember 27, 2026 — Citrix bulletin CTX697096
Discovered/analyzed byLevelBlue Threat Hunt Operations & Research (THOR) team
Earliest known exploitationSeptember 24, 2026 (GreyNoise sensor telemetry, three days pre-disclosure)
Pre-disclosure warningDutch NCSC-NL pre-notification urging Dutch organizations to shut down affected appliances
CISA KEV statusAdded to the Known Exploited Vulnerabilities catalog; federal remediation due September 30, 2026
Key auth-field indicatorVariations of pitboss and NSPPE strings in attacker-controlled authentication data
Second-stage payloadsmain.py (Python reverse shell), update_c08937.pl (Perl post-exploitation script)
Persistence accountsec_monitor, added with superuser role
AttributionNot established; investigation ongoing

How the Attack Chain Worked

The "pitboss" / NSPPE Fingerprint

LevelBlue's THOR team said the single most consistent artifact across the customer environments it examined was attacker-controlled authentication data containing variations of the strings pitboss and NSPPE — a reference to NetScaler's internal Packet Processing Engine. Analysts used this pattern, alongside command-injection telltales like ${IFS} whitespace substitution in authentication fields, to distinguish genuine CVE-2026-88771 exploitation attempts (ranging from basic whoami command testing to full payload staging) from unrelated log noise.

Reverse Shell via main.py

The first second-stage payload LevelBlue documented is main.py, a Python script that overwrites the legitimate /var/python/bin/customsnmpd binary path with attacker code to establish a reverse shell connection to 45.141.21[.]130 over TCP port 443. Before establishing its own foothold, the script actively searches for and kill -9s any running process named /var/python/bin/customsnmpd — removing a legitimate NetScaler SNMP daemon process, likely to free the path for its own persistence and avoid conflicting with the genuine service.

The update_c08937.pl Superuser and Exfiltration Payload

The second payload, update_c08937.pl, is a more comprehensive Perl post-exploitation script retrieved via curl and piped directly into Perl for execution. According to LevelBlue's analysis, it:

  • Modifies /flash/nsconfig/ns.conf to create a local account named sec_monitor and assigns it the superuser role, giving attackers a durable, credential-based backdoor independent of the original exploit chain.
  • Archives the entire /flash/nsconfig directory into /tmp/update_result_3567cs.tgz, then uploads that archive to attacker infrastructure — an attempt to exfiltrate the appliance's full configuration, including certificates and stored credentials.
  • Deletes the staged archive and the script itself after execution, a deliberate anti-forensics step intended to minimize artifacts left behind for incident responders.

Disguising the Web Shell as a CSS File

The most distinctive element of the campaign is how attackers hide their persistence mechanism. The Perl payload modifies NetScaler's HTTP configuration (/etc/httpd.conf) to expose a hidden file — .local_journal, planted under the appliance's logon customization path — as a PHP web shell, then maps requests for it through AliasMatch directives tied to CSS-like URLs resembling legitimate NetScaler assets (patterns similar to receiver.min.[hash].css or LogonUISimple.html.style.min.css). Because the AliasMatch pattern accepts varying hash-like characters in the URL, a wide range of superficially different, CSS-looking requests all route to the same web shell — letting malicious traffic hide in plain sight among an appliance's normal static-asset requests and web server access logs.

Related analysis from GreyNoise, corroborating LevelBlue's findings, described attackers separately setting the setuid and setgid bits on /bin/sh — changing its permissions to 6555 — so that any process later invoking a shell inherits root privileges regardless of the calling account. GreyNoise also documented a password-protected web shell variant at a similar NetScaler logon path that authenticates via a hard-coded cookie value (observed as a CsrfToken cookie) and accepts commands through a second cookie (NSC_TASS) — cookie names deliberately chosen to mimic NetScaler's own NSC_* session-cookie namespace. Google's Threat Intelligence Group (GTIG/Mandiant) has separately tracked related web shell tooling in this campaign under the name WHIPSHOT. Researchers emphasize that patching CVE-2026-88771 alone does not remove any of these artifacts — fixed builds close the vulnerable code path but do not scan for planted files, restore httpd.conf, reset /bin/sh permissions, or delete unauthorized accounts, and high-availability configuration sync has been observed copying web shells to secondary nodes.

Impact Assessment

Impact AreaDescription
Authentication bypassCVE-2026-88771 requires no valid credentials, giving unauthenticated attackers direct command execution on internet-facing appliances
Persistent backdoor accessThe sec_monitor superuser account survives independently of the original exploit and of a routine patch
Configuration and credential exposureArchiving and exfiltrating /flash/nsconfig risks exposure of certificates, stored secrets, and the appliance's full configuration
Stealth and log evasionCSS-disguised web shell URLs and cookie-based command channels are designed to blend into normal appliance web traffic, complicating detection
Anti-forensic behaviorSelf-deleting payloads and archive cleanup reduce the artifacts available for incident response and root-cause analysis
Patch insufficiencyUpdating to fixed NetScaler builds does not remove previously planted accounts, web shells, or modified file permissions
Scale of exposureCISA KEV listing and NCSC-NL's pre-notification indicate exploitation was active and widespread before and immediately after public disclosure

Recommendations

For NetScaler Administrators

  • Apply the fixed builds referenced in Citrix bulletin CTX697096 immediately if not already patched, and treat every internet-facing NetScaler ADC/Gateway appliance that was exposed before patching as potentially compromised.
  • Before or alongside patching, check /flash/nsconfig/ns.conf for an unexpected local account named sec_monitor (or any unrecognized superuser account) and remove it.
  • Inspect /etc/httpd.conf for injected Alias or AliasMatch directives routing CSS-like URLs to unexpected PHP files, and check the logon customization path for a hidden file such as .local_journal.
  • Verify /bin/sh permissions have not been changed to 6555 (setuid/setgid root); reset immediately if found.
  • Check high-availability secondary nodes separately — configuration sync can propagate a web shell from a compromised primary node.

For Security Operations and Threat Hunters

  • Hunt NetScaler authentication logs for strings containing pitboss or NSPPE variations, and for ${IFS} whitespace substitution patterns, both strong indicators of CVE-2026-88771 exploitation attempts.
  • Add detection coverage for outbound connections to known second-stage infrastructure, including 45.141.21[.]130:443, 64.94.85[.]67:443, 23.27.143[.]20:9000, and 31.56.197[.]72:9090.
  • Alert on unexpected processes replacing or impersonating /var/python/bin/customsnmpd, and on kill -9 activity targeting that path.
  • Flag HTTP requests carrying NetScaler-style cookies (for example, unusual CsrfToken or NSC_TASS values) against logon customization paths that should not normally accept command-bearing cookies.

For Incident Responders and Leadership

  • Preserve appliance memory, support bundles, and logs covering at minimum the period since September 24, 2026 before rebuilding or re-imaging any suspected-compromised device.
  • Rotate all credentials and certificates that transited an appliance with confirmed or suspected exploitation, since archived configuration data (/flash/nsconfig) may already have been exfiltrated.
  • Engage dedicated incident response support rather than relying on patching alone — the persistence mechanisms documented here are explicitly designed to survive a routine update.

Key Takeaways

  1. CVE-2026-88771 (CVSS 9.5) is a critical pre-authentication command injection flaw in Citrix NetScaler ADC and NetScaler Gateway, disclosed September 27, 2026 alongside companion flaw CVE-2026-88772.
  2. LevelBlue's THOR team identified attacker-controlled authentication data containing "pitboss" and "NSPPE" strings as the most consistent indicator of CVE-2026-88771 exploitation across multiple customer environments.
  3. Two second-stage payloads were documented: main.py, a Python reverse shell to 45.141.21[.]130:443 that kills legitimate customsnmpd processes, and update_c08937.pl, a Perl script that creates a sec_monitor superuser account and exfiltrates /flash/nsconfig.
  4. The Perl payload disguises a PHP web shell (planted as .local_journal) behind CSS-like URLs using AliasMatch directives, deliberately blending malicious traffic into normal appliance web logs.
  5. Related GreyNoise findings describe attackers setting setuid/setgid 6555 on /bin/sh for guaranteed root access and installing a cookie-authenticated web shell variant, tracked by Google's GTIG/Mandiant under the name WHIPSHOT.
  6. Patching alone does not remove these implants — defenders must independently check for the sec_monitor account, modified httpd.conf, altered /bin/sh permissions, and planted web shell files, including on HA secondary nodes.

Sources