Custom malware is being used in targeted attacks exploiting a Citrix zero-day vulnerability against government agencies, banks, and professional services firms. The attacks leverage previously unknown security flaws in Citrix systems to gain unauthorized access.
Citrix NetScaler was vulnerable to a pre-authentication remote code execution (CVE-2026-88771) exploited through log injection. Attackers embedded base64-encoded bash commands in HTTP User Agent headers and authentication logs; when the ns_monuploadd_err.pl script processed logs, it executed unsanitized grep results, allowing arbitrary command execution and web shell deployment.
Citrix NetScaler ADC and Gateway are affected by multiple remote code execution vulnerabilities (CVE-2026-88771 through CVE-2026-88777). Cloud Software Group urges customers to install updates immediately, with some vulnerabilities affecting all deployments by default while others require specific configurations like DTLS or HTTP to be exploited.