• Sources: CERT-EU, watchTowr analysis, HN discussion
  • Summary: CERT-EU reports that it found exploitation of CVE-2026-88771 in NetScaler logs at the European Court of Auditors and the European Central Bank, an observation independent of the vendor and of the original disclosure, which the 2026-09-28 digest already covered. The post traces the command injection to an unquoted grep result in a Perl monitoring script. Its hunting procedure runs against logs an operator already holds: search the authentication logs for the PPE missed too many heartbeats error string, correlate the INDEX value in the HTTP request logs to recover the intended commands, hunt for base64 in the User-Agent, and check httpd.conf integrity. The CERT-EU post carries no version table, and the fixed builds are 14.1-73.37, 13.1-64.23, 14.1-FIPS 14.1-73.37, and 13.1-37.279 for 13.1-FIPS and 13.1-NDcPP, which rest on watchTowr's transcription of the Citrix bulletin rather than on the vendor page.
  • Why it matters: Any team running NetScaler can run this hunt today without waiting for a vendor scanner, and the INDEX correlation step recovers the commands an attacker intended rather than only proving that an attempt reached the appliance.
  • Follow-up: Watch for attribution and for a count of confirmed compromises, and for whether the same monitoring script carries further injectable paths.

send feedback on this story