By Heath Callahan
Publication Date: 2026-10-02 11:25:00
Analysis
A publicly available Go-based C2 framework is weaponizing Citrix NetScaler appliances as command infrastructure, with 50,277 exposed instances globally and exploitation confirmed since September 21.
CVE-2026-88771, a pre-authentication remote code execution vulnerability in Citrix NetScaler ADC and Gateway appliances, carries a CVSS score of 9.5. It stems from a CWE-20 input validation failure, allowing unauthenticated actors to execute arbitrary commands on critical network infrastructure. This vulnerability is currently being exploited in the wild.
The exploitation chain involves a three-stage command injection process. Unit 42 researchers documented the initial stage as a Base64-encoded dropper hidden within the User-Agent header. This payload interacts with poisoned log entries to trigger the execution of a Perl script. The process bypasses authentication mechanisms entirely, granting attackers access before the appliance verifies the connection.
Persistence is…

