Site icon VMVirtualMachine.com

Citrix NetScaler Platypus C2 — Novel C2 Framework Exploits Pre-Auth RCE Zero-Day

Citrix NetScaler Platypus C2 — Novel C2 Framework Exploits Pre-Auth RCE Zero-Day

By Heath Callahan
Publication Date: 2026-10-02 11:25:00

Analysis

A publicly available Go-based C2 framework is weaponizing Citrix NetScaler appliances as command infrastructure, with 50,277 exposed instances globally and exploitation confirmed since September 21.

CVE-2026-88771, a pre-authentication remote code execution vulnerability in Citrix NetScaler ADC and Gateway appliances, carries a CVSS score of 9.5. It stems from a CWE-20 input validation failure, allowing unauthenticated actors to execute arbitrary commands on critical network infrastructure. This vulnerability is currently being exploited in the wild.

The exploitation chain involves a three-stage command injection process. Unit 42 researchers documented the initial stage as a Base64-encoded dropper hidden within the User-Agent header. This payload interacts with poisoned log entries to trigger the execution of a Perl script. The process bypasses authentication mechanisms entirely, granting attackers access before the appliance verifies the connection.

Persistence is…

Exit mobile version