Summary
- Unit 42 says attackers used CVE-2026-88771 and CVE-2026-88772 to deploy web shells and establish persistence.
- Its telemetry identified 50,277 potentially vulnerable exposed instances as of 27 September.
- Updating removes the vulnerable condition but does not remove attacker persistence established before remediation.
Attackers exploiting recently disclosed NetScaler zero-days were deploying web shells and establishing persistent access before the vulnerabilities became public, according to new analysis that adds technical detail to an exploitation wave already affecting exposed infrastructure across Europe.
NetScaler has released fixes for CVE-2026-88771 and CVE-2026-88772. Subsequent analysis from Palo Alto Networks Unit 42 reconstructs activity that predates disclosure, including device fingerprinting, command injection, and multiple web-shell deployment paths.
Unit 42 says CVE-2026-88771 can provide unauthenticated remote code execution, while CVE-2026-88772 can result in remote code execution or denial of service under affected Datagram Transport Layer Security configurations. Both carry CVSS v4.0 base scores of 9.5.
The more consequential addition is evidence of persistence. Unit 42 observed attackers delivering web shells after exploitation and explicitly warns that updating a compromised appliance will not remove access that has already been established.
That moves the incident beyond the initial patching and exposure questions covered in Cyber Insider’s earlier examination of broad European NetScaler exposure. The newer evidence provides a clearer view of what attackers were doing during the zero-day period.
Unit 42 identified activity beginning on 21 August with requests consistent with version fingerprinting. The same infrastructure subsequently sent similar requests to more than 100 systems, with later activity including different web-shell deployment patterns.
The scale of internet exposure also remains substantial. Cortex Xpanse telemetry identified 50,277 exposed NetScaler instances that could potentially be vulnerable as of 27 September.
That figure is an exposure estimate, not a count of compromised organisations. The distinction becomes particularly important after disclosure because attacker scanning, security research, asset-management systems, and opportunistic internet activity all increase once technical details become public.
For organisations operating NetScaler ADC or Gateway appliances, the response therefore extends beyond whether the current software version is patched. A device exploited before remediation may retain files or other persistence after the vulnerable code has been replaced.
Edge infrastructure complicates that investigation because appliances frequently sit outside conventional endpoint detection coverage. Gateways are deliberately internet-facing, process authentication and application traffic, and occupy trusted positions in front of internal services while often producing less forensic telemetry than general-purpose servers.
The incident fits a wider pattern of attackers targeting perimeter infrastructure directly rather than beginning on an employee endpoint. Compromising gateways, firewalls, VPN systems, and application-delivery appliances can provide an initial foothold before workstation-based security controls become relevant.
Unit 42 says its analysis of post-compromise activity is continuing. The research does not establish the identity of the original operators or the complete number of affected organisations, but it resolves one important uncertainty: attackers were using the vulnerabilities to create persistent access before public disclosure.
That makes historical exposure relevant even after an upgrade. The remaining assessment is not simply whether an appliance is currently vulnerable, but whether it was reachable during the zero-day period and shows evidence that an attacker had already moved beyond initial exploitation.





