Citrix NetScaler was vulnerable to a pre-authentication remote code execution (CVE-2026-88771) exploited through log injection. Attackers embedded base64-encoded bash commands in HTTP User Agent headers and authentication logs; when the ns_monuploadd_err.pl script processed logs, it executed unsanitized grep results, allowing arbitrary command execution and web shell deployment.