# Attackers exploit two NetScaler flaws to install persistent web shells

_Published Friday, October 9, 2026 at 12:11 AM EDT · Security · Latest · Tier 2 — Notable_

![Attackers exploit two NetScaler flaws to install persistent web shells — Primary](https://socprime.com/wp-content/uploads/Image_bg.png)

Attackers are exploiting CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and Gateway appliances to execute code and install web shells for persistent access, SOC Prime reports. The flaws permit remote code execution and memory corruption.

Unit 42 identified activity before disclosure, including version fingerprinting and two web shell delivery techniques. One exploitation chain drops .deb packages; another uses poisoned logs in Perl scripts. Researchers also recovered a PHP web shell that encrypts command communications with RC4.

SOC Prime recommends upgrading Citrix software, isolating vulnerable systems where possible and reviewing Apache configurations for unauthorized changes. Suspected compromises warrant collecting system snapshots and logs and investigating unexpected outbound connections.

## Sources

- [socprime.com](https://socprime.com/active-threats/cve-2026-88771-and-cve-2026-88772-exploited-in-netscaler-attacks/)

---
Canonical: https://techandbusiness.org/newswire/ek3fLiG6gSWPOD8u20XAq6
Published: 2026-10-09T04:11:07.492Z
Story chronology: 2026-10-08T06:41:42.000Z
Retrieved: 2026-10-09T07:47:07.924Z
Publisher: Tech & Business (techandbusiness.org)
