{"id":67128,"date":"2026-10-01T06:24:41","date_gmt":"2026-10-01T13:24:41","guid":{"rendered":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/"},"modified":"2026-10-01T06:24:41","modified_gmt":"2026-10-01T13:24:41","slug":"cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per","status":"publish","type":"post","link":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/","title":{"rendered":"CVE-2026-88771 and CVE-2026-88772: Citrix NetScaler Pre-Auth RCE Detection with Sn1per"},"content":{"rendered":"<p>CVE-2026-88771 and CVE-2026-88772 are two critical remote code execution flaws in Citrix NetScaler ADC and NetScaler Gateway, and both were already being exploited when Citrix disclosed them on 27 September 2026 in bulletin CTX697096 alongside six other vulnerabilities. CISA added both to the Known Exploited Vulnerabilities catalog the same day and set a remediation due date of 30 September, three days later. Google Threat Intelligence Group and Mandiant place the start of the campaign in early September, which means attackers had roughly three weeks of unopposed access before a patch existed. Palo Alto&#8217;s Cortex Xpanse counted 50,277 internet-facing instances on the day of disclosure.<\/p>\n<p>This post is three things. First, a plain-English explanation of what CVE-2026-88771 actually is, because the delivery mechanism is unusual and it changes how you detect it. Second, a Nuclei template you can run right now that identifies the firmware build of a NetScaler appliance without authenticating and without sending anything an incident responder would later have to explain. Third, the harder operational problem: finding every NetScaler on your attack surface, including the ones nobody remembers buying. Credit for the CVE-2026-88771 research goes to Sina Kheirkhah (@SinSinology) of watchTowr, who published the root-cause analysis on 28 September.<\/p>\n<h2>CVE-2026-88771 and CVE-2026-88772 at a glance<\/h2>\n<ul>\n<li><strong>CVE-2026-88771<\/strong> &#8211; CWE-20, improper input validation leading to unauthenticated command execution as root. CVSSv4 9.5 Critical from Citrix as the CNA; CVSS 3.1 9.8 Critical from NVD. Vector <code>CVSS:4.0\/AV:N\/AC:L\/AT:P\/PR:N\/UI:N\/VC:H\/VI:H\/VA:H\/SC:H\/SI:H\/SA:H<\/code>.<\/li>\n<li><strong>CVE-2026-88772<\/strong> &#8211; CWE-119, memory overflow in the DTLS path leading to remote code execution or denial of service. CVSSv4 9.5 Critical from Citrix; <strong>CVSS 3.1 8.1 High from NVD<\/strong>. Vector <code>CVSS:4.0\/AV:N\/AC:H\/AT:N\/PR:N\/UI:N\/VC:H\/VI:H\/VA:H\/SC:H\/SI:H\/SA:H<\/code>.<\/li>\n<li><strong>Affected products<\/strong> &#8211; NetScaler ADC and NetScaler Gateway, customer-managed. CVE-2026-88771 affects every deployment on an affected build, including the default configuration. CVE-2026-88772 requires DTLS, which is enabled by default on Gateway VPN virtual servers.<\/li>\n<li><strong>Fixed builds<\/strong> &#8211; 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1-37.279 for the FIPS and NDcPP lines.<\/li>\n<li><strong>No fix at all<\/strong> &#8211; branches 12.1 and 13.0 are end of life and receive no patch for either CVE.<\/li>\n<li><strong>Exploitation status<\/strong> &#8211; both exploited as zero-days before disclosure. GreyNoise observed CVE-2026-88771 attempts on 24 September, three days before the bulletin. Rapid7 logs a first observation at 14:28:43 UTC on 20 September. A public proof of concept for CVE-2026-88771 was published on 27 September.<\/li>\n<li><strong>Fix now<\/strong> &#8211; upgrade to the CTX697096 builds, then hunt for prior compromise, because patching does not evict an implant.<\/li>\n<\/ul>\n<h3>A disagreement worth knowing about<\/h3>\n<p>The two authorities do not agree on severity, and the gap is wide enough to change a patch queue. For CVE-2026-88772, Citrix scores 9.5 Critical under CVSSv4 while NVD scores 8.1 High under CVSS 3.1. That is one severity band apart. The driver is attack complexity: both agree it is high for CVE-2026-88772, but CVSSv4 weights the downstream subsequent-system impact that 3.1 has no vocabulary for.<\/p>\n<p>Defend for the worse case. A vulnerability being exploited in the wild on an appliance that terminates your VPN is a critical, whatever the arithmetic says.<\/p>\n<p>There is a second contradiction in circulation. One widely syndicated news report names CVE-2026-88778, the TCP initial sequence number prediction issue, as one of the two exploited flaws. Citrix, CISA, Rapid7, Tenable, Unit 42 and watchTowr all name CVE-2026-88771 and CVE-2026-88772. Treat CTX697096 and the KEV catalog as authoritative and the news report as an error, but patch all eight regardless, since they ship in the same firmware image.<\/p>\n<h2>What is CVE-2026-88771?<\/h2>\n<p>NetScaler runs a Perl script called <code>ns_monuploadd_err.pl<\/code> whose job is to process crash and error information from the packet engine. When a packet engine dies, the appliance writes a diagnostic line to a log, and the script later parses that log to work out which engine died and which process ID to clean up.<\/p>\n<p>The flaw is in how the script turns that log text into a filename. It read the engine name and process ID straight out of the log line, built a filename from them, and interpolated the result into a shell command inside backticks around <code>find<\/code>. Nothing validated that the text taken from the log looked like an engine name.<\/p>\n<p>That is a textbook command injection, with one twist that matters enormously for detection: <strong>the attacker does not need to reach the Perl script, and there is no single endpoint to block.<\/strong> The attacker&#8217;s job is only to get their text into the log file. watchTowr&#8217;s analysis notes that failed login attempts, users blocked by rate limiting, request parameters and even <code>User-Agent<\/code> headers can all end up in that log. An unauthenticated request to a pre-auth surface is enough. The script executes the result later, as root.<\/p>\n<p>The delay is real and it is long. The public proof of concept warns that a planted command may take up to 24 hours to be picked up, depending on when the log gets parsed. watchTowr indicated they found a way to force immediate execution and deliberately withheld it.<\/p>\n<p>Three consequences follow, and they are the practical reason this post exists:<\/p>\n<ol>\n<li><strong>You cannot reliably WAF this.<\/strong> There is no one path, parameter or header to filter, because many unrelated pre-auth code paths write user-controlled strings to the same log.<\/li>\n<li><strong>Network detection and execution are separated in time.<\/strong> An IDS rule may fire a day before the command runs. If you see the injection, you are not necessarily too late, which is unusually good news.<\/li>\n<li><strong>Your logs are now both evidence and weapon.<\/strong> The log file investigators need in order to establish prior compromise is the same file an attacker writes into. Hold that thought; it decides how we built the detection template below.<\/li>\n<\/ol>\n<p>Citrix&#8217;s fix in 14.1-73.37 is the right one. The shell pipeline of <code>grep<\/code>, <code>sed<\/code> and <code>awk<\/code> is replaced with native Perl parsing, a strict regular expression that captures only a packet engine name matching <code>NSPPE-\\d{2}<\/code> plus a numeric process ID, and a call to <code>find<\/code> using Perl&#8217;s list form, which never invokes a shell at all.<\/p>\n<p>CVE-2026-88772 is a different animal: a memory overflow reached through DTLS, the datagram variant of TLS that NetScaler Gateway enables by default on VPN virtual servers. Malformed records corrupt packet engine heap memory, which yields either code execution or a crash. Attack complexity is genuinely high, which is why the proof-of-concept tooling published for it generates detection artifacts rather than a working exploit.<\/p>\n<h2>Affected and fixed versions<\/h2>\n<table>\n<thead>\n<tr>\n<th>Product line<\/th>\n<th>Affected builds<\/th>\n<th>Fixed build<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>NetScaler ADC and Gateway 14.1<\/td>\n<td>before 14.1-73.37<\/td>\n<td><strong>14.1-73.37<\/strong><\/td>\n<\/tr>\n<tr>\n<td>NetScaler ADC and Gateway 13.1<\/td>\n<td>before 13.1-64.23<\/td>\n<td><strong>13.1-64.23<\/strong><\/td>\n<\/tr>\n<tr>\n<td>NetScaler ADC 14.1-FIPS<\/td>\n<td>before 14.1-73.37 FIPS<\/td>\n<td><strong>14.1-73.37 FIPS<\/strong><\/td>\n<\/tr>\n<tr>\n<td>NetScaler ADC 13.1-FIPS and NDcPP<\/td>\n<td>before 13.1-37.279<\/td>\n<td><strong>13.1-37.279<\/strong><\/td>\n<\/tr>\n<tr>\n<td>NetScaler ADC and Gateway 12.1<\/td>\n<td>all<\/td>\n<td>none, end of life<\/td>\n<\/tr>\n<tr>\n<td>NetScaler ADC and Gateway 13.0<\/td>\n<td>all<\/td>\n<td>none, end of life<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Four separate floors across four lines, and that is exactly where patch-gap tooling tends to go wrong. A naive &#8220;anything below 14.1-73.37 is vulnerable&#8221; check does the wrong thing twice: it flags a perfectly patched 13.1-64.23 appliance, and if you reverse the comparison it clears a vulnerable 13.1-37.250 FIPS box. Note also that Citrix writes the FIPS floor with dots, <code>13.1-37.279<\/code>, in prose that elsewhere uses the hyphenated form. NVD&#8217;s CPE data carries the same inconsistency, and one NVD CPE range marks <code>14.1-73.37<\/code> FIPS itself as affected with <code>versionEndIncluding<\/code>, which contradicts the bulletin prose naming that exact build as the fix. Any tool doing string-to-version coercion across these lines needs to be tested against the boundaries rather than trusted.<\/p>\n<p>Two more traps:<\/p>\n<p><strong>An upgrade that is staged is not an upgrade that is running.<\/strong> On an HA pair, the appliance answering your probe is the one that happens to hold the VIP. An unpatched standby node is exposed the moment it takes over. Scan both node addresses, not just the virtual IP.<\/p>\n<p><strong>Patching for the previous NetScaler CVE does not help.<\/strong> An appliance updated for CVE-2026-19490 earlier in September is still fully affected by both of these. CTX697096 is a separate firmware floor.<\/p>\n<h2>How the exploit chain works<\/h2>\n<p>The shape of the attack, with the payload position redacted:<\/p>\n<pre><code>POST \/nf\/auth\/doAuthentication.do HTTP\/1.1\nHost: vpn.example.com\nContent-Type: application\/x-www-form-urlencoded\n\nlogin=[REDACTED: a crash-diagnostic-shaped string followed by a shell\n       metacharacter and the attacker's command]&amp;passwd=x\n<\/code><\/pre>\n<p>The mechanism in prose: the submitted value is crafted to imitate a packet engine crash diagnostic, so that when it is written to the error log it will later be read back by <code>ns_monuploadd_err.pl<\/code> as if it were a legitimate engine name. Because the script interpolated that value into a shell command rather than passing it as an argument list, the attacker&#8217;s shell metacharacter terminates the intended command and the remainder runs as root. The authentication endpoint above is one of several pre-auth surfaces that will do; it is not the vulnerability, only a convenient pen for the ink.<\/p>\n<p><strong>We are deliberately not publishing a working exploit here.<\/strong> A public proof of concept already exists, and reproducing it adds nothing for defenders while shortening the distance for everyone else. The same editorial line applies to every advisory in this series, including our <a href=\"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-82329-jfrog-artifactory-auth-bypass-detection-with-sn1per\/\">JFrog Artifactory authentication bypass advisory<\/a>, where the upstream community template was an active exploit that minted admin tokens and ours was a passive version check.<\/p>\n<p>What attackers did after landing is better documented than usual and worth reading as a hunting list. Rapid7 observed command injection running <code>tar<\/code> over <code>\/flash\/nsconfig<\/code>, writing the archive under the web root so it could be retrieved with a single unauthenticated GET. That archive contains <code>ns.conf<\/code>, TLS private keys and stored credentials. Mandiant and others report a PHP web shell at <code>\/var\/netscaler\/logon\/LogonPoint\/custom\/.ctxs.receiver<\/code> with SHA256 <code>ed082f744f035035900f67edf438f2f7d0528ac501234f63d476d65273cdb9a1<\/code>, modifications to <code>httpd.conf<\/code>, and two named implants, WHIPSHOT and a Python tunneler called SLAPSHOT. Some web shell variants answer attacker requests while returning HTTP 404, so a status-code-only sweep of the web root will miss them.<\/p>\n<h2>Am I affected? Quick manual checks<\/h2>\n<p><strong>The authoritative check is local.<\/strong> On the appliance:<\/p>\n<pre><code>show ns version\n<\/code><\/pre>\n<p>Compare against the table above, being careful about which line you are on. Then confirm DTLS state for CVE-2026-88772, remembering that this only narrows the second CVE:<\/p>\n<pre><code>show vpn vserver &lt;name&gt;\n<\/code><\/pre>\n<p>A Gateway virtual server is exposed unless its configuration shows <code>-dtls OFF<\/code>, and any virtual server of type DTLS is exposed by definition. Disabling DTLS is not remediation. CVE-2026-88771 remains independently exploitable and needs no DTLS at all.<\/p>\n<p><strong>The external fingerprint is harder, which is the interesting part.<\/strong> NetScaler advertises no version to unauthenticated clients. The HTTP response headers carry nothing. The login HTML and the JavaScript bundles are byte-identical across builds. That is precisely why Shodan and Censys records for these appliances have no version field, and why a version check adds genuine value over a banner grab.<\/p>\n<p>There are two usable oracles, and neither requires authentication.<\/p>\n<p>The better one is the firmware compile timestamp, a technique originally published by Fox-IT. Every build ships a static language resource at <code>\/vpn\/js\/rdx\/core\/lang\/rdx_en.json.gz<\/code>. The gzip format stores a modification time in the header, bytes 4 through 8, and the firmware build process sets it at compile time. That value maps one to one onto a published build. You can read it by hand:<\/p>\n<pre><code class=\"language-bash\">curl -sk https:\/\/vpn.example.com\/vpn\/js\/rdx\/core\/lang\/rdx_en.json.gz \\\n  | head -c 8 | tail -c 4 | xxd -e -g4 | awk '{print strtonum(&quot;0x&quot;$2)}'\n<\/code><\/pre>\n<p>The second oracle is the pre-logon endpoint analysis package. Gateway has to serve the EPA client to users who have not authenticated yet, so <code>\/epa\/scripts\/linux\/nsepa.deb<\/code> is readable pre-auth, and its length changes between builds. Reading the <code>Content-Length<\/code> header is enough; there is no need to download eleven megabytes.<\/p>\n<p>What the external signal can and cannot tell you: a resolved build is solid evidence of the firmware level and nothing more. It says nothing about whether the box was compromised during the three weeks before the patch existed. And a <em>failure<\/em> to resolve a build means &#8220;unknown, go and check by hand&#8221;, never &#8220;patched&#8221;. More on that blind spot below, because it is the honest limit of this whole approach.<\/p>\n<h2>Nuclei detection template for CVE-2026-88771<\/h2>\n<p>Two templates ship: a reusable firmware fingerprint, and a CTX697096 verdict built on top of it. Both are passive. Both issue nothing but plain GET requests for static files.<\/p>\n<p>The verdict template works by set membership rather than version comparison, and the reason is worth a paragraph. The public build table currently maps 219 firmware builds to compile timestamps, and every single one of them predates every CTX697096 fix floor. We verify that mechanically every time the template is regenerated. So a timestamp hit cannot resolve to a patched appliance, and there is no four-way cross-branch version comparison to get wrong. The 14.1, 13.1, 13.1-FIPS and NDcPP floors stop being a problem because we never compare versions at all.<\/p>\n<pre><code class=\"language-yaml\">id: netscaler-ctx697096-patch-gap\n\ninfo:\n  name: Citrix NetScaler ADC \/ Gateway - CTX697096 Patch Gap (CVE-2026-88771, CVE-2026-88772)\n  author: xer0dayz\n  severity: critical\n  description: |\n    Builds below the CTX697096 fix floors are affected by CVE-2026-88771, an improper\n    input validation flaw allowing unauthenticated command execution, and\n    CVE-2026-88772, a DTLS memory overflow leading to RCE or DoS. Both were added to\n    CISA KEV on 2026-09-27 and both were exploited as zero-days before disclosure.\n\n    This template is NON-DESTRUCTIVE and PASSIVE. It issues a single GET for the static\n    resource \/vpn\/js\/rdx\/core\/lang\/rdx_en.json.gz and reads the firmware compile\n    timestamp from the gzip header MTIME field. It sends no command injection, no SAML\n    message, no DTLS record and no oversized buffer. It does not touch the login\n    endpoint.\n  remediation: |\n    Upgrade to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 (FIPS \/ NDcPP).\n    Branches 12.1 and 13.0 are end of life and have no fix; migrate them.\n    Disabling DTLS mitigates CVE-2026-88772 only. CVE-2026-88771 is independent.\n  reference:\n    - https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX697096\n    - https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-88771\n    - https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-88772\n    - https:\/\/github.com\/fox-it\/citrix-netscaler-triage\n  classification:\n    cvss-metrics: CVSS:4.0\/AV:N\/AC:L\/AT:P\/PR:N\/UI:N\/VC:H\/VI:H\/VA:H\/SC:H\/SI:H\/SA:H\n    cvss-score: 9.5\n    cve-id: CVE-2026-88771\n    cwe-id: CWE-20\n  metadata:\n    verified: false\n    max-request: 2\n    vendor: citrix\n    product: netscaler_application_delivery_controller\n    patched-versions: 14.1-73.37,13.1-64.23,14.1-73.37-FIPS,13.1-37.279\n    kev: true\n    kev-date: 2026-09-27\n    shodan-query: title:&quot;NetScaler Gateway&quot;\n  tags: cve,cve2026,netscaler,citrix,rce,kev,patch-gap,version-detect,passive\n\nhttp:\n  - method: GET\n    path:\n      - &quot;{{BaseURL}}\/vpn\/js\/rdx\/core\/lang\/rdx_en.json.gz&quot;\n      - &quot;{{BaseURL}}\/rdx_en.json.gz&quot;\n\n    stop-at-first-match: true\n    redirects: false\n    matchers-condition: or\n\n    matchers:\n      # Supported branch below its fix floor. A fixed build exists.\n      - type: dsl\n        name: netscaler-known-vulnerable-build\n        dsl:\n          - &quot;status_code == 200&quot;\n          - &quot;starts_with(hex_encode(body), '1f8b')&quot;\n          - &quot;gzip_mtime(body) &gt; 0&quot;\n          - &quot;contains('|1690503901|1762655407| ...219 stamps... |',\n             concat('|', to_string(gzip_mtime(body)), '|'))&quot;\n        condition: and\n\n      # 11.x \/ 12.x \/ 13.0: end of life, no fixed build exists at all.\n      - type: dsl\n        name: netscaler-eol-branch-no-fix-available\n        dsl:\n          - &quot;status_code == 200&quot;\n          - &quot;starts_with(hex_encode(body), '1f8b')&quot;\n          - &quot;gzip_mtime(body) &gt; 0&quot;\n          - &quot;contains('|1535167752|1762830097| ...EOL stamps... |',\n             concat('|', to_string(gzip_mtime(body)), '|'))&quot;\n        condition: and\n\n    extractors:\n      - type: dsl\n        name: firmware_stamp\n        dsl:\n          - &quot;concat('rdx_en_mtime=', to_string(gzip_mtime(body)), ' compiled=',\n             date_time('2006-01-02T15:04:05Z07:00', gzip_mtime(body)))&quot;\n<\/code><\/pre>\n<p>Nuclei does the hard part for you here. <code>gzip_mtime()<\/code> is a first-class DSL function in the engine, so pulling a firmware compile time out of a gzip header is one expression rather than hand-rolled byte slicing. As far as we can tell nobody had pointed it at NetScaler before.<\/p>\n<p>Save and run:<\/p>\n<pre><code class=\"language-bash\">nuclei -t netscaler-ctx697096-patch-gap.yaml -u https:\/\/vpn.example.com\nnuclei -t netscaler-ctx697096-patch-gap.yaml -l netscaler-hosts.txt -jsonl\n<\/code><\/pre>\n<p>A match looks like this:<\/p>\n<pre><code>[netscaler-ctx697096-patch-gap:netscaler-known-vulnerable-build] [http] [critical]\nhttps:\/\/vpn.example.com\/vpn\/js\/rdx\/core\/lang\/rdx_en.json.gz\n[rdx_en_mtime=1762655407 compiled=2025-11-08T21:30:07-05:00]\n<\/code><\/pre>\n<p>Pass that stamp to the bundled <code>cve-2026-88771-detect.py<\/code> and it resolves to an exact build, in this case 14.1-56.74, below the 14.1-73.37 floor.<\/p>\n<h3>Why this template is passive, and why that is not just caution<\/h3>\n<p>There is an obvious active check available. Plant a crash-diagnostic-shaped string in a login field, then look at whether the response reflects it unsanitized. An open community template upstream does roughly that.<\/p>\n<p>We will not ship it, and the reason is specific rather than squeamish. <strong>An active check for this bug writes attacker-shaped text into the exact log file that incident responders need in order to establish prior compromise.<\/strong> This is an appliance CISA has flagged for forensic triage, exploited for three weeks before anyone had a patch, where the vendor&#8217;s own detection script only works if the logs have not yet rotated. Scanning it with a log-poisoning probe contaminates the primary evidence, burns log retention you may need, and makes your own scanner indistinguishable from the intrusion you are trying to rule out. On a fleet of a few hundred appliances you would be manufacturing a few hundred false leads for your own IR team.<\/p>\n<p>A passive build check answers the same question with none of that.<\/p>\n<h3>Two blind spots, stated plainly<\/h3>\n<p><strong>The build table ends on 11 November 2025.<\/strong> The newest builds it maps are 14.1-56.74 and 13.1-61.23. Anything released after that date is unmapped, which means a genuinely vulnerable 14.1-66.x through 14.1-73.36 appliance produces <strong>no finding from this template<\/strong>. Silence means undetermined. It does not mean patched. This is the honest cost of a false-positive-free design, and the companion fingerprint template plus the EPA package size oracle exist to narrow the gap. For anything you care about, confirm with <code>show ns version<\/code>.<\/p>\n<p><strong>Some firmware images are compressed with <code>gzip -n<\/code><\/strong>, which zeroes the timestamp field. The matcher guard rejects a zero, so those hosts also report nothing. Same rule: undetermined, not clean.<\/p>\n<p>A practitioner note while we are here, because it cost us some time: Nuclei&#8217;s <code>date_time()<\/code> does not use strftime tokens. In the <code>%<\/code> form, <code>%m<\/code> yields the minute and <code>%M<\/code> the month, and a bare Go layout such as <code>2006-01-02 15:04:05<\/code> is mangled into a run of digits. Only an offset-bearing layout like <code>2006-01-02T15:04:05Z07:00<\/code> renders correctly, and it renders in the scanning host&#8217;s local zone, not UTC. If you are comparing output against the Fox-IT table, which is published in UTC, use the raw epoch.<\/p>\n<h2>Detecting CVE-2026-88771 across your attack surface with Sn1per<\/h2>\n<p>A patch-gap template is only as good as your host list, and for edge appliances the host list is the actual problem. NetScaler appliances are bought by network teams, deployed for one application, inherited through acquisitions, and stood up as a disaster-recovery pair that nobody has logged into for two years. The ones that stay vulnerable are not the ones your vulnerability scanner knows about. They are the ones nobody remembered they had.<\/p>\n<p>So treat it as a discovery problem before a scanning problem.<\/p>\n<pre><code class=\"language-bash\"># Discover first: subdomains, certificate transparency, ports, services\nsniper -t example.com -m recon -w citrix-audit\n\n# Then the web pass, which fires the CTX697096 templates on every HTTPS port\nsniper -t vpn.example.com -m web -w citrix-audit\n\n# Sweep a known fleet\nsniper -f netscaler-hosts.txt -m webscan -w citrix-audit\n<\/code><\/pre>\n<p>Both templates drop into <code>\/sniper\/templates\/nuclei\/server\/<\/code> and need no configuration change, because <code>NUCLEI_TEMPLATES<\/code> is a directory list that Nuclei recurses. Findings surface as P1 CRITICAL in the workspace, carrying the matcher name and the build stamp. Pull them out of a Professional or Enterprise install over the API:<\/p>\n<pre><code class=\"language-bash\">curl -sk -H &quot;X-API-Key: $SN1PER_API_KEY&quot; \\\n  &quot;https:\/\/sn1per.local\/pro\/api.php?action=vulnerabilities&amp;workspace=citrix-audit&quot; \\\n  | jq -r '.[] | select(.name | test(&quot;CTX697096&quot;)) | [.host, .severity, .details] | @tsv'\n<\/code><\/pre>\n<p>One more reason this particular job belongs on infrastructure you control. The output of this scan is a ranked list of your unpatched internet-facing VPN concentrators, during a window when a working exploit is public. That is not a document to hand to a multi-tenant SaaS scanner and hope about. Sn1per runs on your own hardware, in your own network, and the results stay there. We wrote about the general version of this argument in <a href=\"https:\/\/sn1persecurity.com\/wordpress\/external-attack-surface-management-with-sn1per\/\">external attack surface management with Sn1per<\/a> and compared the self-hosted options in <a href=\"https:\/\/sn1persecurity.com\/wordpress\/open-source-self-hosted-attack-surface-management-tools\/\">open source self-hosted attack surface management tools<\/a>.<\/p>\n<h2>Which Sn1per edition fits<\/h2>\n<table>\n<thead>\n<tr>\n<th>Capability<\/th>\n<th>Community<\/th>\n<th><a href=\"https:\/\/sn1persecurity.com\/wordpress\/product\/sn1per-professional-2026-license\/\">Professional 2026<\/a><\/th>\n<th><a href=\"https:\/\/sn1persecurity.com\/wordpress\/product\/sn1per-enterprise\/\">Enterprise<\/a><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Run the CTX697096 templates<\/td>\n<td>Yes<\/td>\n<td>Yes<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td>Curated Nuclei set maintained for you<\/td>\n<td>Partial<\/td>\n<td>Yes<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td>Workspaces and scan history<\/td>\n<td>Basic<\/td>\n<td>Yes<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td>Web UI with asset risk ranking<\/td>\n<td>No<\/td>\n<td>Yes<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td>JSON API for finding export<\/td>\n<td>No<\/td>\n<td>Yes<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td>Scheduled recurring surface sweeps<\/td>\n<td>No<\/td>\n<td>Limited<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td>Multi-user, delegated workspaces<\/td>\n<td>No<\/td>\n<td>No<\/td>\n<td>Yes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>For a one-off answer to &#8220;are any of our NetScalers unpatched&#8221;, Community plus the template is enough. For the recurring version of that question, which is the one that actually matters given NetScaler has produced five KEV entries in 2026 alone, you want scheduling and history. There is more on that trade-off in our write-up of <a href=\"https:\/\/sn1persecurity.com\/wordpress\/automated-pentest-tools\/\">automated penetration testing tools<\/a>.<\/p>\n<h2>Remediation and mitigation<\/h2>\n<ol>\n<li><strong>Upgrade to the CTX697096 builds now.<\/strong> 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 for FIPS and NDcPP. The federal deadline was 30 September; there is no reading of this where waiting is reasonable.<\/li>\n<li><strong>Migrate 12.1 and 13.0 appliances.<\/strong> There is no patch. A CVSS 9.5 with no vendor fix path on an internet-facing VPN concentrator is an architectural problem, not a patching one, and it should sit above the merely-unpatched boxes in your queue.<\/li>\n<li><strong>Patch both HA nodes.<\/strong> Check the standby by address, not through the VIP.<\/li>\n<li><strong>Assume breach, and do it before you reboot into the new image.<\/strong> Exploitation ran for roughly three weeks before a fix existed. Preserve the appliance logs and a configuration snapshot first. Citrix offers IOC scanning through NetScaler Console on 14.1-73.36 or later with telemetry enabled, but states its own IOC set does not cover every known technique, and the vendor script depends on logs that may already have rotated. A clean IOC scan is weak evidence.<\/li>\n<li><strong>Hunt for the known artifacts.<\/strong> The web shell path <code>\/var\/netscaler\/logon\/LogonPoint\/custom\/.ctxs.receiver<\/code> and its SHA256, unexpected <code>httpd.conf<\/code> modifications, stray archives under the GUI web root, and DTLS handshake failures followed by a packet engine crash. Remember the 404-returning web shell variants and the up-to-24-hour delay between injection and execution, which means your log review window needs to start well before the first suspicious execution.<\/li>\n<li><strong>Rotate everything the appliance held.<\/strong> TLS private keys, service account credentials in <code>ns.conf<\/code>, LDAP and RADIUS bind passwords, session signing material. If the configuration archive was exfiltrated, all of it is burned. Patching does not revoke a credential.<\/li>\n<li><strong>Reduce the surface afterwards.<\/strong> Management interfaces should not be internet-facing. Turn DTLS off where no client needs it, understanding that this narrows CVE-2026-88772 only.<\/li>\n<\/ol>\n<h2>Frequently asked questions<\/h2>\n<p><strong>What is CVE-2026-88771?<\/strong><br \/>\nIt is an improper input validation vulnerability, CWE-20, in Citrix NetScaler ADC and NetScaler Gateway that lets an unauthenticated attacker run arbitrary commands as root. The attacker gets their text into an appliance log, and a Perl crash-handling script later reads that text back and interpolates it into a shell command. Citrix scores it CVSSv4 9.5 and NVD scores it CVSS 3.1 9.8. It affects the default configuration, so no special feature needs to be enabled.<\/p>\n<p><strong>Which NetScaler versions are affected by CVE-2026-88771 and CVE-2026-88772?<\/strong><br \/>\nNetScaler ADC and Gateway before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 for the FIPS and NDcPP lines. Branches 12.1 and 13.0 are end of life and get no fix for either CVE. Patching for the earlier CVE-2026-19490 does not cover these.<\/p>\n<p><strong>Are CVE-2026-88771 and CVE-2026-88772 being exploited in the wild?<\/strong><br \/>\nYes. Both were exploited as zero-days before Citrix published CTX697096, and CISA added both to the KEV catalog on 27 September 2026 with a three-day remediation deadline. Google Threat Intelligence Group and Mandiant date the campaign to early September, affecting government, financial services, education, legal and professional services organizations in North America and Europe. A public proof of concept for CVE-2026-88771 appeared on 27 September.<\/p>\n<p><strong>How do I detect CVE-2026-88771 remotely if NetScaler does not report its version?<\/strong><br \/>\nRead the firmware compile timestamp out of the gzip header of <code>\/vpn\/js\/rdx\/core\/lang\/rdx_en.json.gz<\/code>, which maps one to one onto a published build. The Nuclei template above does this with the engine&#8217;s native <code>gzip_mtime()<\/code> function, and the bundled Python script resolves the timestamp to an exact build string. Be aware the public build table ends in November 2025, so a newer appliance will come back undetermined rather than clean.<\/p>\n<p><strong>Is disabling DTLS enough to fix this?<\/strong><br \/>\nNo, and this is the most common mistake being made with this bulletin. Disabling DTLS removes exposure to CVE-2026-88772 only. CVE-2026-88771 needs no DTLS and remains fully exploitable against an unpatched appliance in its default configuration. Only the firmware upgrade addresses both.<\/p>\n<p><strong>Is the Nuclei template safe to run against production appliances?<\/strong><br \/>\nYes. It sends two plain GET requests for static files and reads metadata from the response. No command injection, no SAML message, no DTLS record, no oversized buffer, and it never touches the login endpoint. We deliberately avoided the available active check because it would write attacker-shaped strings into the same logs your incident responders need, on appliances flagged for forensic triage.<\/p>\n<h2>Closing<\/h2>\n<p>The interesting thing about CVE-2026-88771 is not that an edge appliance had a command injection. It is that the delivery vehicle was a log file. The vulnerable code was never reachable directly, the entry point was any one of a dozen unrelated pre-auth paths, and execution happened up to a day later. Signature-based detection struggles with all three properties. Knowing precisely what firmware every appliance on your perimeter is running does not struggle with any of them, which is why a boring build inventory keeps outperforming clever detection on exactly this class of bug.<\/p>\n<p>NetScaler has produced five CISA KEV entries in the first nine months of 2026. There will be a sixth. The build fingerprint template is the part of this work that keeps paying, because it answers the next advisory too.<\/p>\n<p>Grab the templates, run them across every HTTPS port you own rather than just the hosts you remember, and if you find an appliance below the floor, preserve the evidence before you reboot it.<\/p>\n<p><script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@graph\": [\n    {\n      \"@type\": \"FAQPage\",\n      \"mainEntity\": [\n        {\n          \"@type\": \"Question\",\n          \"name\": \"What is CVE-2026-88771?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"It is an improper input validation vulnerability, CWE-20, in Citrix NetScaler ADC and NetScaler Gateway that lets an unauthenticated attacker run arbitrary commands as root. The attacker gets their text into an appliance log, and a Perl crash-handling script later reads that text back and interpolates it into a shell command. Citrix scores it CVSSv4 9.5 and NVD scores it CVSS 3.1 9.8. It affects the default configuration, so no special feature needs to be enabled.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Which NetScaler versions are affected by CVE-2026-88771 and CVE-2026-88772?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"NetScaler ADC and Gateway before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 for the FIPS and NDcPP lines. Branches 12.1 and 13.0 are end of life and get no fix for either CVE. Patching for the earlier CVE-2026-19490 does not cover these.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Are CVE-2026-88771 and CVE-2026-88772 being exploited in the wild?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Yes. Both were exploited as zero-days before Citrix published CTX697096, and CISA added both to the KEV catalog on 27 September 2026 with a three-day remediation deadline. Google Threat Intelligence Group and Mandiant date the campaign to early September, affecting government, financial services, education, legal and professional services organizations in North America and Europe. A public proof of concept for CVE-2026-88771 appeared on 27 September.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"How do I detect CVE-2026-88771 remotely if NetScaler does not report its version?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Read the firmware compile timestamp out of the gzip header of `\/vpn\/js\/rdx\/core\/lang\/rdx_en.json.gz`, which maps one to one onto a published build. The Nuclei template above does this with the engine's native `gzip_mtime()` function, and the bundled Python script resolves the timestamp to an exact build string. Be aware the public build table ends in November 2025, so a newer appliance will come back undetermined rather than clean.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Is disabling DTLS enough to fix this?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"No, and this is the most common mistake being made with this bulletin. Disabling DTLS removes exposure to CVE-2026-88772 only. CVE-2026-88771 needs no DTLS and remains fully exploitable against an unpatched appliance in its default configuration. Only the firmware upgrade addresses both.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Is the Nuclei template safe to run against production appliances?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Yes. It sends two plain GET requests for static files and reads metadata from the response. No command injection, no SAML message, no DTLS record, no oversized buffer, and it never touches the login endpoint. We deliberately avoided the available active check because it would write attacker-shaped strings into the same logs your incident responders need, on appliances flagged for forensic triage.\"\n          }\n        }\n      ]\n    },\n    {\n      \"@type\": \"TechArticle\",\n      \"headline\": \"CVE-2026-88771 and CVE-2026-88772: Citrix NetScaler Pre-Auth RCE - Advisory + Nuclei Detection\",\n      \"description\": \"CVE-2026-88771 and CVE-2026-88772 are actively exploited NetScaler RCE zero-days. Fixed builds, patch-gap analysis, and a passive Nuclei template.\",\n      \"url\": \"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/\",\n      \"author\": {\n        \"@type\": \"Organization\",\n        \"name\": \"Sn1perSecurity LLC\"\n      },\n      \"publisher\": {\n        \"@type\": \"Organization\",\n        \"name\": \"Sn1perSecurity LLC\"\n      },\n      \"about\": [\n        {\n          \"@type\": \"Thing\",\n          \"name\": \"CVE-2026-88771\"\n        },\n        {\n          \"@type\": \"Thing\",\n          \"name\": \"CVE-2026-88772\"\n        }\n      ]\n    }\n  ]\n}\n<\/script><\/p>\n<div id=\"wp-share-button-67128\" class=\"wp-share-button theme28\"><span class=\"total-share \"><i class=\"total-count-text\">Total Share<\/i> <i class=\"total-count\">0<\/i> <\/span><a target=\"_blank\" href=\"https:\/\/www.facebook.com\/sharer\/sharer.php?u=https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/\" class=\"share-button share-button-67128 facebook\" id=\"facebook\" data-nonce=\"b9f8cfa3df\">\r\n\r\n<span class=\"button-icon\"><\/span>\r\n<span class=\"button-name\">Facebook<\/span>\r\n\r\n<span class=\"button-count\">0<\/span>\r\n\r\n<\/a>\r\n\r\n<a target=\"_blank\" href=\"https:\/\/twitter.com\/intent\/tweet?url=https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/&amp;text=CVE-2026-88771%20and%20CVE-2026-88772:%20Citrix%20NetScaler%20Pre-Auth%20RCE%20Detection%20with%20Sn1per\" class=\"share-button share-button-67128 twitter\" id=\"twitter\" data-nonce=\"b9f8cfa3df\">\r\n\r\n<span class=\"button-icon\"><\/span>\r\n<span class=\"button-name\">Twitter<\/span>\r\n\r\n<span class=\"button-count\">0<\/span>\r\n\r\n<\/a>\r\n\r\n<a target=\"_blank\" href=\"http:\/\/www.reddit.com\/submit?title=CVE-2026-88771%20and%20CVE-2026-88772:%20Citrix%20NetScaler%20Pre-Auth%20RCE%20Detection%20with%20Sn1per&amp;url=https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/\" class=\"share-button share-button-67128 reddit\" id=\"reddit\" data-nonce=\"b9f8cfa3df\">\r\n\r\n<span class=\"button-icon\"><\/span>\r\n<span class=\"button-name\">Reddit<\/span>\r\n\r\n<span class=\"button-count\">0<\/span>\r\n\r\n<\/a>\r\n\r\n<a target=\"_blank\" href=\"https:\/\/www.linkedin.com\/shareArticle?url=https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/&amp;title=CVE-2026-88771%20and%20CVE-2026-88772:%20Citrix%20NetScaler%20Pre-Auth%20RCE%20Detection%20with%20Sn1per&amp;summary=&amp;source=\" class=\"share-button share-button-67128 linkedin\" id=\"linkedin\" data-nonce=\"b9f8cfa3df\">\r\n\r\n<span class=\"button-icon\"><\/span>\r\n<span class=\"button-name\">Linkedin<\/span>\r\n\r\n<span class=\"button-count\">0<\/span>\r\n\r\n<\/a>\r\n\r\n<a title=\"More...\" href=\"#wp-share-button-67128\" class=\"share-button-more\"><span class=\"button-icon\"><i class=\"fa fa-plus\"><\/i><\/span><\/a><div class=\"wp-share-button-popup wp-share-button-popup-67128\"><div class=\"popup-buttons\"><span class=\"close\">X<\/span><a target=\"_blank\" href=\"mailto:?subject=CVE-2026-88771%20and%20CVE-2026-88772:%20Citrix%20NetScaler%20Pre-Auth%20RCE%20Detection%20with%20Sn1per&amp;body=https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/\" class=\"share-button share-button-67128 email\" id=\"email\">\r\n\r\n<span class=\"button-icon\"><\/span>\r\n<span class=\"button-name\">Email<\/span>\r\n<span class=\"button-count\">0<\/span>\t\t\t\t\r\n\r\n<\/a>\r\n<\/div><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>CVE-2026-88771 and CVE-2026-88772 are actively exploited Citrix NetScaler RCE zero-days in CISA KEV. Get the passive Nuclei template, the four-branch patch-gap logic, and how to detect unpatched appliances at scale with Sn1per.<\/p>\n","protected":false},"author":1,"featured_media":67129,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[290,99,184,289,338,335],"tags":[],"class_list":["post-67128","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-attack-surface-management","category-cves","category-news","category-penetration-testing","category-threat-intelligence","category-vulnerability-scanning"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"CVE-2026-88771 and CVE-2026-88772 are actively exploited NetScaler RCE zero-days. Fixed builds, patch-gap analysis, and a passive Nuclei template.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"xer0dayz\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Sn1perSecurity\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"CVE-2026-88771 and CVE-2026-88772: NetScaler RCE | Sn1per\" \/>\n\t\t<meta property=\"og:description\" content=\"CVE-2026-88771 and CVE-2026-88772 are actively exploited NetScaler RCE zero-days. Fixed builds, patch-gap analysis, and a passive Nuclei template.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/10\/cve-88771-cover.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/10\/cve-88771-cover.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-10-01T13:24:41+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-10-01T13:24:41+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Sn1persecurity-105784611869093\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@sn1persecurity\" \/>\n\t\t<meta name=\"twitter:title\" content=\"CVE-2026-88771 and CVE-2026-88772: NetScaler RCE | Sn1per\" \/>\n\t\t<meta name=\"twitter:description\" content=\"CVE-2026-88771 and CVE-2026-88772 are actively exploited NetScaler RCE zero-days. Fixed builds, patch-gap analysis, and a passive Nuclei template.\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@sn1persecurity\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/10\/cve-88771-cover.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\\\/#blogposting\",\"name\":\"CVE-2026-88771 and CVE-2026-88772: NetScaler RCE | Sn1per\",\"headline\":\"CVE-2026-88771 and CVE-2026-88772: Citrix NetScaler Pre-Auth RCE Detection with Sn1per\",\"author\":{\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/author\\\/xer0dayz\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/cve-88771-cover.png\",\"width\":1200,\"height\":630,\"caption\":\"CVE-2026-88771 and CVE-2026-88772 Citrix NetScaler pre-auth RCE, fixed build per line\"},\"datePublished\":\"2026-10-01T06:24:41-07:00\",\"dateModified\":\"2026-10-01T06:24:41-07:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\\\/#webpage\"},\"articleSection\":\"Attack Surface Management, CVE's, News, Penetration Testing, Threat Intelligence, Vulnerability Scanning\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/category\\\/cves\\\/#listItem\",\"name\":\"CVE's\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/category\\\/cves\\\/#listItem\",\"position\":2,\"name\":\"CVE's\",\"item\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/category\\\/cves\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\\\/#listItem\",\"name\":\"CVE-2026-88771 and CVE-2026-88772: Citrix NetScaler Pre-Auth RCE Detection with Sn1per\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\\\/#listItem\",\"position\":3,\"name\":\"CVE-2026-88771 and CVE-2026-88772: Citrix NetScaler Pre-Auth RCE Detection with Sn1per\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/category\\\/cves\\\/#listItem\",\"name\":\"CVE's\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/#organization\",\"name\":\"Sn1perSecurity\",\"description\":\"Get an attacker's view of your organization with our all-in-one offensive security platform\",\"url\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/\",\"email\":\"support@sn1persecurity.com\",\"foundingDate\":\"2021-10-05\",\"numberOfEmployees\":{\"@type\":\"QuantitativeValue\",\"value\":2},\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/Sn1perwhiteandcircleicontwitter.jpg\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\\\/#organizationLogo\",\"width\":500,\"height\":500,\"caption\":\"Sn1perSecurity Logo\"},\"image\":{\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Sn1persecurity-105784611869093\",\"https:\\\/\\\/x.com\\\/sn1persecurity\",\"https:\\\/\\\/www.instagram.com\\\/sn1persecurity\",\"https:\\\/\\\/www.youtube.com\\\/sn1persecurity\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/sn1persecurity\\\/\",\"https:\\\/\\\/github.com\\\/1N3\\\/Sn1per\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/author\\\/xer0dayz\\\/#author\",\"url\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/author\\\/xer0dayz\\\/\",\"name\":\"xer0dayz\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e5f1a4e7b520f257ee62dcb2a44274bc57e37aa9fe3e3dcd511755464f80f636?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"xer0dayz\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\\\/#webpage\",\"url\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\\\/\",\"name\":\"CVE-2026-88771 and CVE-2026-88772: NetScaler RCE | Sn1per\",\"description\":\"CVE-2026-88771 and CVE-2026-88772 are actively exploited NetScaler RCE zero-days. Fixed builds, patch-gap analysis, and a passive Nuclei template.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/author\\\/xer0dayz\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/author\\\/xer0dayz\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/cve-88771-cover.png\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\\\/#mainImage\",\"width\":1200,\"height\":630,\"caption\":\"CVE-2026-88771 and CVE-2026-88772 Citrix NetScaler pre-auth RCE, fixed build per line\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\\\/#mainImage\"},\"datePublished\":\"2026-10-01T06:24:41-07:00\",\"dateModified\":\"2026-10-01T06:24:41-07:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/#website\",\"url\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/\",\"name\":\"Sn1perSecurity\",\"alternateName\":\"Sn1per\",\"description\":\"Get an attacker's view of your organization with our all-in-one offensive security platform\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"CVE-2026-88771 and CVE-2026-88772: NetScaler RCE | Sn1per","description":"CVE-2026-88771 and CVE-2026-88772 are actively exploited NetScaler RCE zero-days. Fixed builds, patch-gap analysis, and a passive Nuclei template.","canonical_url":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/#blogposting","name":"CVE-2026-88771 and CVE-2026-88772: NetScaler RCE | Sn1per","headline":"CVE-2026-88771 and CVE-2026-88772: Citrix NetScaler Pre-Auth RCE Detection with Sn1per","author":{"@id":"https:\/\/sn1persecurity.com\/wordpress\/author\/xer0dayz\/#author"},"publisher":{"@id":"https:\/\/sn1persecurity.com\/wordpress\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/10\/cve-88771-cover.png","width":1200,"height":630,"caption":"CVE-2026-88771 and CVE-2026-88772 Citrix NetScaler pre-auth RCE, fixed build per line"},"datePublished":"2026-10-01T06:24:41-07:00","dateModified":"2026-10-01T06:24:41-07:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/#webpage"},"isPartOf":{"@id":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/#webpage"},"articleSection":"Attack Surface Management, CVE's, News, Penetration Testing, Threat Intelligence, Vulnerability Scanning"},{"@type":"BreadcrumbList","@id":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/sn1persecurity.com\/wordpress\/#listItem","position":1,"name":"Home","item":"https:\/\/sn1persecurity.com\/wordpress\/","nextItem":{"@type":"ListItem","@id":"https:\/\/sn1persecurity.com\/wordpress\/category\/cves\/#listItem","name":"CVE's"}},{"@type":"ListItem","@id":"https:\/\/sn1persecurity.com\/wordpress\/category\/cves\/#listItem","position":2,"name":"CVE's","item":"https:\/\/sn1persecurity.com\/wordpress\/category\/cves\/","nextItem":{"@type":"ListItem","@id":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/#listItem","name":"CVE-2026-88771 and CVE-2026-88772: Citrix NetScaler Pre-Auth RCE Detection with Sn1per"},"previousItem":{"@type":"ListItem","@id":"https:\/\/sn1persecurity.com\/wordpress\/#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/#listItem","position":3,"name":"CVE-2026-88771 and CVE-2026-88772: Citrix NetScaler Pre-Auth RCE Detection with Sn1per","previousItem":{"@type":"ListItem","@id":"https:\/\/sn1persecurity.com\/wordpress\/category\/cves\/#listItem","name":"CVE's"}}]},{"@type":"Organization","@id":"https:\/\/sn1persecurity.com\/wordpress\/#organization","name":"Sn1perSecurity","description":"Get an attacker's view of your organization with our all-in-one offensive security platform","url":"https:\/\/sn1persecurity.com\/wordpress\/","email":"support@sn1persecurity.com","foundingDate":"2021-10-05","numberOfEmployees":{"@type":"QuantitativeValue","value":2},"logo":{"@type":"ImageObject","url":"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/06\/Sn1perwhiteandcircleicontwitter.jpg","@id":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/#organizationLogo","width":500,"height":500,"caption":"Sn1perSecurity Logo"},"image":{"@id":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/Sn1persecurity-105784611869093","https:\/\/x.com\/sn1persecurity","https:\/\/www.instagram.com\/sn1persecurity","https:\/\/www.youtube.com\/sn1persecurity","https:\/\/www.linkedin.com\/in\/sn1persecurity\/","https:\/\/github.com\/1N3\/Sn1per"]},{"@type":"Person","@id":"https:\/\/sn1persecurity.com\/wordpress\/author\/xer0dayz\/#author","url":"https:\/\/sn1persecurity.com\/wordpress\/author\/xer0dayz\/","name":"xer0dayz","image":{"@type":"ImageObject","@id":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/e5f1a4e7b520f257ee62dcb2a44274bc57e37aa9fe3e3dcd511755464f80f636?s=96&d=mm&r=g","width":96,"height":96,"caption":"xer0dayz"}},{"@type":"WebPage","@id":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/#webpage","url":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/","name":"CVE-2026-88771 and CVE-2026-88772: NetScaler RCE | Sn1per","description":"CVE-2026-88771 and CVE-2026-88772 are actively exploited NetScaler RCE zero-days. Fixed builds, patch-gap analysis, and a passive Nuclei template.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/sn1persecurity.com\/wordpress\/#website"},"breadcrumb":{"@id":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/#breadcrumblist"},"author":{"@id":"https:\/\/sn1persecurity.com\/wordpress\/author\/xer0dayz\/#author"},"creator":{"@id":"https:\/\/sn1persecurity.com\/wordpress\/author\/xer0dayz\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/10\/cve-88771-cover.png","@id":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/#mainImage","width":1200,"height":630,"caption":"CVE-2026-88771 and CVE-2026-88772 Citrix NetScaler pre-auth RCE, fixed build per line"},"primaryImageOfPage":{"@id":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/#mainImage"},"datePublished":"2026-10-01T06:24:41-07:00","dateModified":"2026-10-01T06:24:41-07:00"},{"@type":"WebSite","@id":"https:\/\/sn1persecurity.com\/wordpress\/#website","url":"https:\/\/sn1persecurity.com\/wordpress\/","name":"Sn1perSecurity","alternateName":"Sn1per","description":"Get an attacker's view of your organization with our all-in-one offensive security platform","inLanguage":"en-US","publisher":{"@id":"https:\/\/sn1persecurity.com\/wordpress\/#organization"}}]},"og:locale":"en_US","og:site_name":"Sn1perSecurity","og:type":"article","og:title":"CVE-2026-88771 and CVE-2026-88772: NetScaler RCE | Sn1per","og:description":"CVE-2026-88771 and CVE-2026-88772 are actively exploited NetScaler RCE zero-days. Fixed builds, patch-gap analysis, and a passive Nuclei template.","og:url":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/","og:image":"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/10\/cve-88771-cover.png","og:image:secure_url":"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/10\/cve-88771-cover.png","og:image:width":1200,"og:image:height":630,"article:published_time":"2026-10-01T13:24:41+00:00","article:modified_time":"2026-10-01T13:24:41+00:00","article:publisher":"https:\/\/www.facebook.com\/Sn1persecurity-105784611869093","twitter:card":"summary_large_image","twitter:site":"@sn1persecurity","twitter:title":"CVE-2026-88771 and CVE-2026-88772: NetScaler RCE | Sn1per","twitter:description":"CVE-2026-88771 and CVE-2026-88772 are actively exploited NetScaler RCE zero-days. Fixed builds, patch-gap analysis, and a passive Nuclei template.","twitter:creator":"@sn1persecurity","twitter:image":"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/10\/cve-88771-cover.png"},"aioseo_meta_data":{"post_id":"67128","title":"CVE-2026-88771 and CVE-2026-88772: NetScaler RCE | Sn1per","description":"CVE-2026-88771 and CVE-2026-88772 are actively exploited NetScaler RCE zero-days. Fixed builds, patch-gap analysis, and a passive Nuclei template.","keywords":null,"keyphrases":{"focus":{"keyphrase":"CVE-2026-88771","score":0,"analysis":[]}},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2026-10-01 13:24:41","updated":"2026-10-01 13:25:41","seo_analyzer_scan_date":null,"focus_keyword":"CVE-2026-88771","additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/sn1persecurity.com\/wordpress\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/sn1persecurity.com\/wordpress\/category\/cves\/\" title=\"CVE&apos;s\">CVE's<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tCVE-2026-88771 and CVE-2026-88772: Citrix NetScaler Pre-Auth RCE Detection with Sn1per\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/sn1persecurity.com\/wordpress\/"},{"label":"CVE's","link":"https:\/\/sn1persecurity.com\/wordpress\/category\/cves\/"},{"label":"CVE-2026-88771 and CVE-2026-88772: Citrix NetScaler Pre-Auth RCE Detection with Sn1per","link":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-88771-citrix-netscaler-preauth-rce-detection-with-sn1per\/"}],"jetpack_shortlink":"https:\/\/wp.me\/pdnW96-hsI","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":17988,"url":"https:\/\/sn1persecurity.com\/wordpress\/vmware-workspace-one-access-freemarker-ssti-cve-2022-22954-detection-with-sn1per-professional\/","url_meta":{"origin":67128,"position":0},"title":"VMware Workspace ONE Access freemarker SSTI (CVE-2022-22954) Detection with Sn1per Professional","author":"xer0dayz","date":"April 14, 2022","format":false,"excerpt":"Information regarding a critical 0-day vulnerability affecting the VMware Workspace ONE Access and Identity Manager was disclosed and designated CVE-2022-22954 which allows an un-authenticated attacker to execute arbitrary code on vulnerable servers. On April 14th, CISA & US-Cert added CVE-2022-22954 to their catalog of known exploited vulnerabilities after a number\u2026","rel":"","context":"In &quot;Attack Surface Management&quot;","block_context":{"text":"Attack Surface Management","link":"https:\/\/sn1persecurity.com\/wordpress\/category\/attack-surface-management\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/04\/Sn1per-cve-2022-22954-detection1.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/04\/Sn1per-cve-2022-22954-detection1.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/04\/Sn1per-cve-2022-22954-detection1.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/04\/Sn1per-cve-2022-22954-detection1.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/04\/Sn1per-cve-2022-22954-detection1.png?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/04\/Sn1per-cve-2022-22954-detection1.png?resize=1400%2C800&ssl=1 4x"},"classes":[]},{"id":65542,"url":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-61511-vbulletin-preauth-rce-detection-with-sn1per\/","url_meta":{"origin":67128,"position":1},"title":"CVE-2026-61511: Pre-Auth Remote Code Execution in vBulletin (runMaths) &#8211; Advisory + Nuclei Detection","author":"xer0dayz","date":"July 31, 2026","format":false,"excerpt":"CVE-2026-61511 is a critical unauthenticated RCE in vBulletin 5.x and 6.x, caused by eval injection in the runMaths() template handler. A plain-English advisory, a tested non-destructive Nuclei detection template, the 6.x patch-level trap that hides unpatched hosts, and how to find vulnerable vBulletin at scale with Sn1per.","rel":"","context":"In &quot;Attack Surface Management&quot;","block_context":{"text":"Attack Surface Management","link":"https:\/\/sn1persecurity.com\/wordpress\/category\/attack-surface-management\/"},"img":{"alt_text":"Sn1perSecurity advisory cover: CVE-2026-61511 unauthenticated eval injection RCE in vBulletin runMaths, with a Nuclei detection template and Sn1per attack surface detection","src":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/07\/cve-2026-61511-vbulletin.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/07\/cve-2026-61511-vbulletin.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/07\/cve-2026-61511-vbulletin.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/07\/cve-2026-61511-vbulletin.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/07\/cve-2026-61511-vbulletin.png?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":25699,"url":"https:\/\/sn1persecurity.com\/wordpress\/sn1per-enterprise-v20231025-released\/","url_meta":{"origin":67128,"position":2},"title":"Sn1per Enterprise v20231025 Released!","author":"xer0dayz","date":"October 29, 2023","format":false,"excerpt":"We are pleased to announce the release of Sn1per Enterprise v20231025, packed with a multitude of new features and improvements exclusively for our Sn1per Enterprise customers. This blog post will provide a comprehensive overview of these latest additions. If you haven't joined the Sn1per Enterprise community yet, feel free to\u2026","rel":"","context":"In &quot;News&quot;","block_context":{"text":"News","link":"https:\/\/sn1persecurity.com\/wordpress\/category\/news\/"},"img":{"alt_text":"Sn1per-Enterprise-Released1","src":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/05\/Sn1per-Enterprise-Released1.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/05\/Sn1per-Enterprise-Released1.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/05\/Sn1per-Enterprise-Released1.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/05\/Sn1per-Enterprise-Released1.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/05\/Sn1per-Enterprise-Released1.png?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/05\/Sn1per-Enterprise-Released1.png?resize=1400%2C800&ssl=1 4x"},"classes":[]},{"id":26771,"url":"https:\/\/sn1persecurity.com\/wordpress\/cve-2024-21733-apache-tomcat-http-request-smuggling\/","url_meta":{"origin":67128,"position":3},"title":"CVE-2024-21733 Apache Tomcat HTTP Request Smuggling","author":"xer0dayz","date":"January 21, 2024","format":false,"excerpt":"Our security research team recently discovered a critical \"0day\" vulnerability which was assigned CVE-2024-21733. The vulnerability was discovered by xer0dayz from Sn1perSecurity LLC and allows attackers to force a victim's browser to de-synchronize its connection with websites hosted on top of Apache Tomcat, causing sensitive data to be smuggled from\u2026","rel":"","context":"In &quot;Attack Surface Management&quot;","block_context":{"text":"Attack Surface Management","link":"https:\/\/sn1persecurity.com\/wordpress\/category\/attack-surface-management\/"},"img":{"alt_text":"CVE-2024-21733 Apache Tomcat HTTP Request Smuggling","src":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2024\/01\/CVE-2024-21733.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2024\/01\/CVE-2024-21733.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2024\/01\/CVE-2024-21733.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2024\/01\/CVE-2024-21733.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2024\/01\/CVE-2024-21733.png?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2024\/01\/CVE-2024-21733.png?resize=1400%2C800&ssl=1 4x"},"classes":[]},{"id":18193,"url":"https:\/\/sn1persecurity.com\/wordpress\/big-ip-icontrol-rest-rce-cve-2022-1388-detection-with-sn1per-professional\/","url_meta":{"origin":67128,"position":4},"title":"BIG-IP iControl REST RCE (CVE-2022-1388) Detection with Sn1per Professional","author":"xer0dayz","date":"May 10, 2022","format":false,"excerpt":"A critical vulnerability affecting the F5 BIG-IP devices was disclosed and designated CVE-2022-1388 which allows an un-authenticated attacker to execute arbitrary code on vulnerable servers. A number of Proof-of-Concept (PoC) exploits were published online and exploit activity is actively being observed. Given the impact and severity of the vulnerability, Sn1perSecurity\u2026","rel":"","context":"In &quot;Attack Surface Management&quot;","block_context":{"text":"Attack Surface Management","link":"https:\/\/sn1persecurity.com\/wordpress\/category\/attack-surface-management\/"},"img":{"alt_text":"Sn1per-CVE-2022-1388-Scanner1","src":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/05\/Sn1per-CVE-2022-1388-Scanner1.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/05\/Sn1per-CVE-2022-1388-Scanner1.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/05\/Sn1per-CVE-2022-1388-Scanner1.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/05\/Sn1per-CVE-2022-1388-Scanner1.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/05\/Sn1per-CVE-2022-1388-Scanner1.png?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/05\/Sn1per-CVE-2022-1388-Scanner1.png?resize=1400%2C800&ssl=1 4x"},"classes":[]},{"id":66330,"url":"https:\/\/sn1persecurity.com\/wordpress\/cve-2026-82329-jfrog-artifactory-auth-bypass-detection-with-sn1per\/","url_meta":{"origin":67128,"position":5},"title":"CVE-2026-82329: JFrog Artifactory Auth Bypass Detection with Sn1per","author":"xer0dayz","date":"September 3, 2026","format":false,"excerpt":"CVE-2026-82329 is a critical, unauthenticated JFrog Artifactory authentication bypass in CISA KEV. Get the passive Nuclei template, the six-branch version logic, and how to detect it at scale with Sn1per.","rel":"","context":"In &quot;Attack Surface Management&quot;","block_context":{"text":"Attack Surface Management","link":"https:\/\/sn1persecurity.com\/wordpress\/category\/attack-surface-management\/"},"img":{"alt_text":"CVE-2026-82329 JFrog Artifactory unauthenticated admin takeover, fixed release per branch","src":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/09\/cve-82329-cover.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/09\/cve-82329-cover.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/09\/cve-82329-cover.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/09\/cve-82329-cover.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/09\/cve-82329-cover.png?resize=1050%2C600&ssl=1 3x"},"classes":[]}],"jetpack_featured_media_url":"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2026\/10\/cve-88771-cover.png","_links":{"self":[{"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/posts\/67128","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/comments?post=67128"}],"version-history":[{"count":0,"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/posts\/67128\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/media\/67129"}],"wp:attachment":[{"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/media?parent=67128"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/categories?post=67128"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/tags?post=67128"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}