Date: 10/01/2026
Severity: High
Summary
Threat actors are actively exploiting two critical NetScaler ADC and Gateway vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated CVSS 4.0: 9.5. CVE-2026-88771 enables unauthenticated remote code execution through improper input validation, while CVE-2026-88772 can cause RCE or DoS through a DTLS memory overflow. Attackers have used these zero-days to deploy web shells and establish initial access and persistence, with 50,277 potentially exposed instances identified by Cortex Xpanse as of September 27, 2026.
Indicators of Compromise (IOC) List
IP Address | 45.61.136.143 66.227.183.84 77.83.199.39 104.28.215.137 104.248.244.66 104.28.247.136 162.33.178.9 193.149.176.207 216.245.184.164 |
Hash | 1bd314b661396c7086f6367fbbb48025e03ca2de69c073d53a8b0a38aa5fbb7d
79c65fa04541032e251fa4796b97800374b63c7982593dd1a2e0db605d429186
ae22ef2517b5c0fb47f78745b9cb5260acee0e751b89bcd354640ff8bc8d29ec
|
Filenames | /vpn/scripts/linux/nsgclient18.deb /vpn/scripts/linux/nsg64.deb /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | dstipaddress IN ("66.227.183.84","216.245.184.164","45.61.136.143","104.28.247.136","77.83.199.39","193.149.176.207","104.248.244.66") or srcipaddress IN ("66.227.183.84","216.245.184.164","45.61.136.143","104.28.247.136","77.83.199.39","193.149.176.207","104.248.244.66") |
Detection Query 2 : | sha256hash IN ("1bd314b661396c7086f6367fbbb48025e03ca2de69c073d53a8b0a38aa5fbb7d"."79c65fa04541032e251fa4796b97800374b63c7982593dd1a2e0db605d429186","ae22ef2517b5c0fb47f78745b9cb5260acee0e751b89bcd354640ff8bc8d29ec")
|
Detection Query 3 : | resourcename = "Windows Security" AND eventtype = "4663" AND (objectname like "/vpn/scripts/linux/nsgclient18.deb" or objectname like "/vpn/scripts/linux/nsg64.deb" or objectname like "/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver") |
Detection Query 4 : | technologygroup = "EDR" AND (objectname like "/vpn/scripts/linux/nsgclient18.deb" or objectname like "/vpn/scripts/linux/nsg64.deb" or objectname like "/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver") |
Reference:
https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/