Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

    Date: 10/01/2026

    Severity: High

    Summary

    Threat actors are actively exploiting two critical NetScaler ADC and Gateway vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated CVSS 4.0: 9.5. CVE-2026-88771 enables unauthenticated remote code execution through improper input validation, while CVE-2026-88772 can cause RCE or DoS through a DTLS memory overflow. Attackers have used these zero-days to deploy web shells and establish initial access and persistence, with 50,277 potentially exposed instances identified by Cortex Xpanse as of September 27, 2026.  

    Indicators of Compromise (IOC) List  

    IP Address

    45.61.136.143

    66.227.183.84

    77.83.199.39

    104.28.215.137

    104.248.244.66

    104.28.247.136

    162.33.178.9

    193.149.176.207

    216.245.184.164

    Hash

    1bd314b661396c7086f6367fbbb48025e03ca2de69c073d53a8b0a38aa5fbb7d

    79c65fa04541032e251fa4796b97800374b63c7982593dd1a2e0db605d429186

    ae22ef2517b5c0fb47f78745b9cb5260acee0e751b89bcd354640ff8bc8d29ec

    Filenames

    /vpn/scripts/linux/nsgclient18.deb

    /vpn/scripts/linux/nsg64.deb

    /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    dstipaddress IN ("66.227.183.84","216.245.184.164","45.61.136.143","104.28.247.136","77.83.199.39","193.149.176.207","104.248.244.66") or srcipaddress IN ("66.227.183.84","216.245.184.164","45.61.136.143","104.28.247.136","77.83.199.39","193.149.176.207","104.248.244.66")

    Detection Query 2 :

    sha256hash IN ("1bd314b661396c7086f6367fbbb48025e03ca2de69c073d53a8b0a38aa5fbb7d"."79c65fa04541032e251fa4796b97800374b63c7982593dd1a2e0db605d429186","ae22ef2517b5c0fb47f78745b9cb5260acee0e751b89bcd354640ff8bc8d29ec")

    Detection Query 3 :

    resourcename = "Windows Security" AND eventtype = "4663" AND (objectname like "/vpn/scripts/linux/nsgclient18.deb" or objectname like "/vpn/scripts/linux/nsg64.deb" or objectname like "/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver")

    Detection Query 4 :

    technologygroup = "EDR" AND (objectname like "/vpn/scripts/linux/nsgclient18.deb" or objectname like "/vpn/scripts/linux/nsg64.deb" or objectname like "/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver")

    Reference:    

    https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/


    Tags

    VulnerabilityExploitCVE-2026Zero-day

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags