By Varshini
Publication Date: 2026-10-08 06:23:00
Attackers are exploiting a critical vulnerability in Citrix NetScaler ADC and NetScaler Gateway to run commands, create privileged accounts, and install web shells.
LevelBlue’s Threat Hunt Operations & Research (THOR) team identified malicious authentication events during investigations across multiple customer environments.
The flaw, CVE-2026-88771, allows attackers to execute arbitrary commands without authentication. It carries a CVSS score of 9.5, and patches are available.
LevelBlue reported that exploitation was occurring globally, with CISA adding the vulnerability to its Known Exploited Vulnerabilities catalog.
The latest investigation examined activity beyond initial exploitation. Researchers found command execution tests, payload downloads, configuration collection, reverse shells, and attempts to steal appliance configuration data.
These findings show why defenders must investigate what happened after a suspicious authentication request.

