The attacks centre on two vulnerabilities that Citrix disclosed on Sunday as CVE-2026-88771 and CVE-2026-88772, which some researchers have dubbed "PitScaler." Citrix confirmed both flaws had been exploited on unmitigated NetScaler deployments and released security updates to address them.
CVE-2026-88771 is an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled.
The campaign first came to light over the weekend, when Citrix administrators reported that IT suppliers, security teams, CERTs and national cybersecurity agencies had privately warned organisations about two unpatched NetScaler zero-days, in some cases advising them to shut down affected appliances. Cybersecurity firm watchTowr later said it had verified reports that both remote code execution flaws were being exploited in the wild and that Citrix was preparing patches.
GreyNoise said it observed a threat actor attempting to exploit a Citrix NetScaler Gateway on September 24, three days before Citrix publicly disclosed the flaws. The attack originated from IP address 149.104.78.141. GreyNoise said the attacker attempted to modify /bin/sh to provide a root shell, install a password-protected PHP web shell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver, and alter /etc/httpd.conf so requests for what appeared to be CSS files, including receiver.min.css, would instead open the hidden web shell.
GreyNoise is not publishing the full exploit for now, but recommends defenders hunt for the .ctxs.receiver file, related Alias or AliasMatch entries in httpd.conf, changes to the permissions of /bin/sh, and connections from the observed source IP.
Mandiant has released a report providing further detail on how CVE-2026-88772 is being exploited, confirming the attacks began in at least early September.