Threat hunters have reported post-exploitation activity against Citrix NetScaler ADC and Gateway systems that includes attacker-created superuser accounts and web shells mapped to paths resembling CSS resources. The activity follows exploitation of the critical pre-authentication command-injection vulnerability CVE-2026-88771.

The reported tradecraft underscores how quickly perimeter-device compromise can become durable access. In addition to initial command execution, attackers were observed pursuing configuration data and persistence mechanisms designed to blend into ordinary web traffic.

What to do now

  • Apply Citrix fixes and mitigations for affected NetScaler systems, following the vendor’s guidance.
  • Hunt for unexpected administrator accounts, modified authentication events and unusual URL mappings.
  • Review configuration exports, web-server files and outbound connections for signs of post-exploitation activity.
  • Preserve logs before making disruptive changes if compromise is suspected.

This is an example of why patch status alone is not a complete answer when active exploitation has been reported: teams should pair remediation with focused threat hunting.

Source: The Hacker News report on NetScaler post-exploitation activity.

By Allan