Image: Help Net Security
Attackers are broadly scanning for internet-exposed Citrix NetScaler ADC and Gateway systems that remain vulnerable to CVE-2026-88771. Organizations running these appliances should patch promptly and check for signs of compromise, rather than treating an update alone as proof that no earlier intrusion occurred.
Exploitation shifts to mass scanning
Help Net Security reports that exploitation moved from stealthy zero-day activity to widespread, opportunistic attacks after watchTowr Labs published technical analysis and a proof-of-concept exploit. A proof of concept is code that demonstrates how a security flaw can be exploited.Lupovis CEO Xavier Bellekens said the company’s sensors recorded attempts within minutes of the exploit’s release. The activity targeted exposed, unpatched appliances across the internet rather than a narrow set of organizations.
- CVE-2026-88771 can be exploited remotely on unpatched devices using the default configuration.
- Citrix says both CVE-2026-88771 and CVE-2026-88772 were exploited as zero-days, meaning attackers used them before fixes were available.
What defenders should check
Citrix supplied a compromise-detection script, but warned that it may miss real intrusions because attackers can change their methods and infrastructure. Administrators should combine it with log and DNS checks instead of relying on the script alone.- Search for POST requests to /nf/auth/doAuthentication.do whose body unexpectedly contains “pitboss PPE unexpectedly died NSPPE.”
- Look for outbound DNS requests ending in instances.httpworkbench.com; Lupovis said this indicates that a system has already been hit.
- Investigate connections involving 138.199.200.90, which Lupovis linked to stolen-data collection in observed attacks.
Thousands of systems remain exposed
Censys counted about 42,000 internet-facing NetScaler ADC or Gateway hosts, although its scanning cannot determine which are vulnerable or compromised. Security researcher Kevin Beaumont separately estimated that fewer than 10% of exposed hosts were patched and said he was tracking more than 100 victim organizations.Beaumont said each tracked victim had a unique webshell, a malicious script that gives attackers remote access. He believes the initial attackers were pursuing espionage, while no public proof-of-concept code was available for CVE-2026-88772 at the time of the report.